Commit Graph
15011 Commits
Author SHA1 Message Date
e7fc1b2e2e feat: restricted job tokens per script and flow (#11484)
* feat: restricted job tokens (job_token_scopes on scripts and flows)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: admit flow-run reads, skip dedicated workers, gate on worker version

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep restricted jobs off flow runners, preserve scopes on rename and promotion

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep restricted jobs off every dedicated handoff, confine progress flow id

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: exclude restricted runnables from dedicated worker startup

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: gate restrictions on the release after 1.821.0

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: store per-job scopes on job_perms instead of v2_job, pin inline runs to the checked version

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: step-level job_token_scopes for flow steps and agent tools

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: fail closed on perms read errors, refuse restricted queue imports, gate step scopes in previews

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: carry a job's scopes on its completion so a re-run keeps the caller's cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: carry a zombie job's scopes into its completion

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: leave a zombie for the next sweep when its scopes cannot be read

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* docs: correct the QueuedJobV2 completion comment

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: validate step scopes in batch flows, fail closed on unvalidated step scopes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: refuse flows with step or tool restrictions at push while an older worker is live

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: apply the step-scope worker gate to flow restarts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: list the job token toggle with the other step and flow settings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* chore: pin the EE companion merged with EE main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* perf: skip scope lookups for unrestricted jobs; list job token setting last

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* style: rustfmt scopes tests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: confine restricted job tokens to their own run lineage; drop remaining extra lookups

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* chore: update ee-repo-ref to 259ad3bfeef5285ba80eedc86309b11dca001220

This commit updates the EE repository reference after PR #843 was merged in windmill-ee-private.

Previous ee-repo-ref: 2b77c0225dca441235daf7bf0a06ba968df0c927

New ee-repo-ref: 259ad3bfeef5285ba80eedc86309b11dca001220

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-03 09:33:44 +02:00
Ruben Fiszel e952298f84 feat: replace the AI input filling toggle with an additional prompt (#11501)
* feat: replace the AI input filling toggle with an additional prompt for AI

* feat: pass the additional prompt for AI to MCP clients and shared AI guidance

* feat: shrink the run page AI card to a button and a collapsed prompt

* fix: offer writers a way to add a prompt for AI from the run page
2026-10-03 09:33:18 +02:00
Ruben FiszelandClaude Opus 5.5 b7f74cd562 fix: never reuse a pg connection a script left inside a transaction (#11497)
* fix: never reuse a pg connection a script left inside a transaction

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: close a pg connection whose job failed instead of caching it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* docs: describe every caller of PgConnectionLease::discard

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:03:44 +02:00
Ruben FiszelandClaude Opus 5.5 f2393e5b24 keep flow priority input inline with its toggle on wide screens (#11500)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:00:32 +02:00
Ruben FiszelandClaude Opus 5.5 68f8f19b33 fix: keep a resource default set in the schema when the script is redeployed (#11495)
* fix: keep a resource default set in the schema when the script is redeployed

Fixes #11493

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a schema resource default only while the arg stays that resource type

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: drop a scalar resource default when the arg becomes a list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 08:57:04 +02:00
Ruben FiszelandClaude Opus 5.5 d7227726be feat: log pg job progress, warn on stalls, detect dead db connections (#11491)
* feat: log pg job progress, warn on stalls, detect dead db connections

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: log only slow pg steps to keep job log writes off fast statements

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: say when a slow connect included a failed cached-connection reset

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 22:26:37 +02:00
Ruben FiszelandClaude Opus 5.5 eed7e7d9e6 fix: stop the pg executor cache from pinning a pooler slot (#11490)
* fix: stop the pg executor cache from pinning a pooler slot

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test: retry while the evicted pg backend exits

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 22:21:58 +02:00
d949484e7b feat: read the OIDC signing key from a file and rotate it (#11482)
* feat: read the OIDC signing key from a file and rotate it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rmQBQKBgsrd4dJ55vv8n5

* chore: update ee-repo-ref to fe47a306d3760ac2d5a8e14365f05a3503a3ac35

This commit updates the EE repository reference after PR #841 was merged in windmill-ee-private.

Previous ee-repo-ref: 7bd97ee7ce32188a171df9190af990d84586752b

New ee-repo-ref: fe47a306d3760ac2d5a8e14365f05a3503a3ac35

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 22:18:32 +02:00
99e96d3f78 fix: let instances withhold signing secrets from the settings API (#11483)
* fix: never return the instance signing secrets from the settings API

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: tell wmill instance get-config users that jwt_secret is not exported

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: point ee-repo-ref at the oidc signing key fix

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: block rsa_keys from agent workers and keep get-config stdout pure yaml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep server secrets in exports by default behind EXPORT_SERVER_SECRETS

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 43b2ce8866a393b2666b17647ddb1466afc70bb1

This commit updates the EE repository reference after PR #842 was merged in windmill-ee-private.

Previous ee-repo-ref: 3a0d0c3f45eeb9f5fe8d50ce3798239aa9101a22

New ee-repo-ref: 43b2ce8866a393b2666b17647ddb1466afc70bb1

Automated by sync-ee-ref workflow.

* fix: withhold server secrets on any non-true EXPORT_SERVER_SECRETS value

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 19:25:04 +02:00
Ruben FiszelandClaude Opus 5.5 98274a7336 fix: let legacy draft-only items be discarded from the home page (#11488)
* fix: let legacy draft-only items be discarded from the home page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: describe the legacy draft move guard as it now is

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 19:11:50 +02:00
Ruben FiszelandClaude Opus 5.5 920771b598 keep tagged binary prebuilds off the dependency job tag (#11489)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 19:07:50 +02:00
4beb1f9420 feat: add trigger, tag, run-as and digest claims to job OIDC tokens (#11481)
* feat: add trigger, tag, run-as and digest claims to job OIDC tokens

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: parse digest floats exactly and derive the codebase digest like push

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: give flows that reference flow nodes no digest and keep --json clean

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: list flow step digests from module positions only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test: skip the pulled module-script digest check on windows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 71b8c1042fd8188c2d2882476f12b671cb5ba421

This commit updates the EE repository reference after PR #840 was merged in windmill-ee-private.

Previous ee-repo-ref: ba1870536789a43c5b6ec18522a93edb9cb07f3d

New ee-repo-ref: 71b8c1042fd8188c2d2882476f12b671cb5ba421

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 19:02:17 +02:00
Ruben FiszelandClaude Opus 5.5 4bc7e0d7ba feat: add a cancel-only jobs:cancel token scope, optionally path-scoped (#11479)
* feat: add a cancel-only jobs:cancel token scope, optionally path-scoped

jobs:cancel grants the four cancel routes (cancel, force cancel, cancel
selection, cancel persistent) and nothing else; jobs:write keeps covering
them. With paths, the handlers only cancel a job whose own runnable path,
or a parent flow's, matches; others get the invisible-job NotFound.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: confine cancel_selection like the by-id cancel routes

A token that also carries a path-scoped jobs:run scope is confined to
those runnables on the by-id cancels (through the job read check), so
apply the same run confinement to each selected job.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: confine persistent cancels, admit agent runs, batch selection checks

cancel_persistent applies the run-scope confinement the other cancel routes
apply; a path-scoped jobs:cancel admits agent runs under the agent's path,
recognized as the run-scope read check does; cancel_selection checks the
cancel scope in one query.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: let a jobs:cancel grant stand on its own on the cancel routes

Intersecting cancels with the token's jobs:run scopes did not hold: the
token could mint itself a child carrying only the cancel scope. The cancel
routes now apply the cancel paths and the usual per-job visibility, and
leave the run-scope read confinement to reads, as jobs:write does.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 18:59:37 +02:00
Ruben FiszelandClaude Opus 5.5 3d1d249556 feat: add an instance setting routing all dependency jobs to one tag (#11486)
* feat: add an instance setting routing all dependency jobs to one tag

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep bunnative locks on bun and explain the default dependency routing

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 18:40:32 +02:00
Ruben FiszelandClaude Opus 5.5 14801fdd68 fix: unstick postgres jobs on large results with custom-typed columns (#11475)
* fix: unstick postgres jobs on large results with custom-typed columns

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: carry the parked-rows delivery fix in the postgres fork

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: describe postgres queries before streaming instead of parking rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf: skip the postgres describe for statements that return no rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: look for returning in the whole postgres statement

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: read the leading postgres keyword past nested block comments

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: end leading postgres line comments at CR too

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 17:21:20 +02:00
Ruben FiszelandClaude Opus 5.5 ae093b7666 fix: read inet and cidr results with their prefix, including arrays (#11476)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 15:56:11 +02:00
Ruben Fiszelandrubenfiszel fee401f01e chore(main): release 1.821.0 (#11432)
* chore(main): release 1.821.0

* Apply automatic changes

---------

Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com>
v1.821.0
2026-10-01 18:35:57 +02:00
hugocasaandClaude Opus 5.5 64f0e87d57 oauth: add github scope_options (gist, read:org) (#11471)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:35:44 +02:00
153b02a5de fix: offer user scopes in the slack scope editor and drop the generated description on type change (#11464)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
2026-10-01 18:31:23 +02:00
hugocasaandClaude Opus 5.5 f74113c75a post ai eval results to the workspace-prefixed cloud route (#11473)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:26:34 +02:00
Diego Imbert 26be1d7da8 feat: add test key button to AI resource drawers (#11466)
* feat: add test key button to AI resource drawers

* fix: scope-check inline AI resource values and keep test model editable

* fix: keep test model editable for unsaved resources, own-key provider check
2026-10-01 18:25:49 +02:00
GuilhemandClaude Opus 5.5 88d0cd00e5 fix: restore the save to workspace button on inline flow steps (#11469)
* fix: restore the save to workspace button on inline flow steps

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: make the inline step save to workspace button icon only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 18:25:25 +02:00
hugocasaandClaude Opus 5.5 7f1beadf79 feat: add wmill datatable migrate status (#11465)
* feat: add wmill datatable migrate status

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: show unpushed local migrations in datatable migrate status

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: move pushLocalMigrations doc comment back onto its function

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:22:04 +02:00
hugocasaandClaude Opus 5.5 c72ae8f7d4 oauth: offer granular gcal read scopes (calendar list, metadata, free/busy) (#11459)
Keeps the calendar.events default. Adds calendarlist.readonly, calendars.readonly
and freebusy as labelled scope_options so the hub's get_calendar_list,
get_calendar_metadata and free/busy scripts can be granted least-privilege.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:21:52 +02:00
hugocasaandClaude Opus 5.5 ab2de838d7 feat: offer slack write scopes as bot and user scope options (#11472)
* fix: offer user scopes in the slack scope editor and drop the generated description on type change

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: offer slack write scopes as bot and user scope options

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:20:36 +02:00
Ruben FiszelandClaude Opus 5.5 8c92e63ffc chore(docker): bump bundled crane to v0.22.1 (#11470)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 18:17:55 +02:00
Ruben FiszelandClaude Opus 5.5 1c6758a656 fix(npm-proxy): support _auth and username/_password basic auth from npmrc (#11467)
* fix: send npmrc basic auth (_auth, username/_password) from the npm proxy

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: resolve npmrc credentials from parent paths like npm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: honor empty npmrc overrides and keep registry credentials to its origin

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 17:52:47 +02:00
GuilhemandClaude Opus 5 b10f83c763 feat(sessions): show an item's deployed page in the preview panel (#11458)
* feat(sessions): show an item's deployed page in the preview panel

The preview panel showed an item's editor and nothing else. It now shows the
deployed page too, as a tab of its own.

**Two sides, two tabs.** The editor and the deployed page are different things
to look at, so `isItemTabFor` keys on the side rather than the item: asking for
a side already open focuses it, asking for the other opens it alongside. Two
editors for one item still cannot coexist — they would race its single
(kind, path) cell — but an editor beside a viewer is safe, since the viewer
reads the deployed version over the API and holds no cell. The tab breadcrumb
keeps re-pointing in place; `Exit & see details` and the detail page's `Edit`
open the other side instead of consuming the one you are on. A tab's label
carries `(edit)` when it is the editor side.

**The detail pages moved out of their routes.** `/scripts/get` and `/flows/get`
are now thin wrappers over `ScriptDetail` and `FlowDetail`, which the panel
renders too. Everything they reach — drawers, triggers, saved inputs — is scoped
to the viewer's workspace through `setOperatingWorkspace`, and every navigation
they attempt is caught by `interceptNav` and turned into a move inside the
panel, so nothing takes the browser out of the session. A plain click is
intercepted; ⌘-click and middle-click still open a real tab, which is why the
pages keep their `href`s.

**The picker opens what exists.** A row opens the deployed page, or the editor
when nothing is deployed there, and carries a Draft / Draft only badge in the
review dock's words. `WorkspaceItem` gained `draftOnly` and `hasDraft` from the
listers, which already returned both; deploys now invalidate the picker cache
through `itemDeployed`, so a just-deployed item stops reading as a draft. Rows
also carry a hover Edit action, reachable from the keyboard with the pick
modifier.

`open_preview` gained a `mode`, narrowed out of the advertised schema for a
session that cannot write drafts and re-checked per path in the handler, where
a refusal reports "couldn't check" apart from "denied". The mode is resolved
before those checks, so a call that omits it is gated as the editor it will
become.

Alongside, the workspace a detail page acts on is now the one it is showing
rather than the one the browser is navigated to: `MoveDrawer`,
`toggleWorkspaceErrorHandler` and the pages' own permission gates read the
operating workspace and its acting user, and `RunForm` mints a password
argument's ephemeral variable there too — in a fork session all of these
previously answered for the parent. `InWorkspaceAppViewer` hands the app's
`ctx` user down as a prop instead of writing the global `userStore`, which from
a session tab was re-pointing every permission check on the page.

Fixes found on the way: `DetailPageLayout` claimed `h-screen` inside a panel
that is not the viewport; Edit on a historical script version dropped the
version from the intercepted click; the Run button stayed spinning after a run
that left the page mounted; and the window-level run shortcut fired from a
collapsed panel and from keys another handler had already claimed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(sessions): historical edits, stale not-found, shared edit rights, tab labels

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep deployed-page links and workspace reads in the session

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): scope detail hrefs to the session, re-point the viewer's own tab

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep a previewed raw app's route out of the session URL

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): resolve edit-in-fork against the session workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): read advanced run tags from the session workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): fork from the session workspace, star only navigation items

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): mount only the side a preview tab shows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): address CI review round 1 findings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): route links in a deployed page's drawers through the panel

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): tell the chat which deployed page the panel shows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): only a 404 reads as an undeployed raw app

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): scope the unparseable-JSON run gate to the form

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): a flow deleted from the panel stays in its tab

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): the picker's edit shortcut works on the current row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): load-error toasts say what failed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep an oversized invalid JSON editor in its form's run gate

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* revert: keep main's draft_only description in openapi.yaml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-10-01 17:43:52 +02:00
d518aa5557 feat: let slack connects issue a user token via user_scope (#11452)
* feat: let slack connects issue a user token via user_scope

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: keep trailing newline in ee-repo-ref

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: bump ee-repo-ref

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: name the provider in slack token descriptions and refresh them on reconnect

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: drop the generated slack description when connecting another provider

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: drop the slack scope pin migration, slack ignores scope on refresh

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: clear the generated slack description on client-credentials connects too

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: update ee-repo-ref to ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7

This commit updates the EE repository reference after PR #837 was merged in windmill-ee-private.

Previous ee-repo-ref: 83298dcf23574d5ed05e6c767bf1d9b067ab7a95

New ee-repo-ref: ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-01 14:53:22 +02:00
227e934210 feat: harden job OIDC tokens with version claims, jti and a lifetime cap (#11457)
* feat: harden job OIDC tokens with version claims, jti and a lifetime cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: count restarted flow nodes as latest only if the current version uses them

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: follow stored loop and branch bodies when resolving current flow nodes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: bind current flow nodes to their step id and skip non-numeric node keys

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: derive flow step currency from the flow above it and restarts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: treat every restarted job but a version-checked flow as not latest

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: count a restarted body as latest when the run it came from was current

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to b469efc9ceddfaaa1040e4cb2c18993822f92c78

This commit updates the EE repository reference after PR #838 was merged in windmill-ee-private.

Previous ee-repo-ref: 25e0b9ae1c6c60419a479fa38d5dc5928832790a

New ee-repo-ref: b469efc9ceddfaaa1040e4cb2c18993822f92c78

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-01 14:09:36 +02:00
Ruben FiszelandClaude Opus 5.5 d2830cb4a0 fix: stop running deleted script versions from worker caches (#11456)
* fix: stop running deleted script versions from worker caches

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: reuse script cache invalidate and test the deletion notify payload

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a deleted copy from shadowing the same hash in another workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: drop deletions missed while down and fills racing the eviction

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: batch deletion events, evict path caches and cover version pruning

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: evict the raw-import cache on both passes and split large deletion events

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 13:37:00 +02:00
hugocasaandClaude Opus 5.5 840567fbe5 feat: labelled scope checkboxes in the oauth connect dialog (#11460)
* feat: show human labels for oauth scope options in the connect dialog

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: always show scope checkboxes, label gdocs and gchat scopes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: offer default scopes as checkboxes for every oauth provider

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 13:29:02 +02:00
GuilhemandClaude Opus 5.5 ddde41bc1d fix: block runs while a JSON input does not parse (#11463)
* fix: block runs while a JSON input does not parse

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clear json editor error on unmount and flush editors before run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: restore validity when a nullable arg input is cleared

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: let field editors parse before the run check and reset the message on view switch

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clear the run refusal message when form validity changes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 13:28:41 +02:00
Ruben FiszelandClaude Opus 5.5 5bd2c2c254 drop unused mut that breaks the backend integration test build (#11462)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 11:13:45 +02:00
Ruben Fiszel f1d970bd1a ci: move CI AI models to opus 5.5, gpt-6.1 sol and deepseek v4.1 (#11461)
* ci: move CI AI models to opus 5.5, gpt-6 and deepseek v4.1 flash

* test: point the deepseek eval alias at v4.1 flash

* ci: run the codex review on gpt-6.1-sol with codex cli 0.159.3
2026-10-01 11:11:57 +02:00
dependabot[bot] 94924d4644 chore(deps): bump docker/build-push-action from 5 to 7 (#11421)
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 5 to 7.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/v5...v7)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 10:49:45 +02:00
Ruben FiszelandClaude Opus 5.5 c25bb1ed90 feat: add //no_network annotation for native scripts (#11445)
* feat: add //no_network annotation to deny all network access in native scripts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: close no_network bypasses (quic dns, header parsing, token, non-native)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: refuse //no_network on deno regardless of //native, derive disabled ops from deno_net

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: scope //no_network to native scripts only, drop bun/deno refusal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 10:47:28 +02:00
hugocasaandClaude Opus 5.5 bba58c4167 oauth: add gdocs and gchat providers (#11447)
* oauth: add gdocs and gchat providers, gchat icon

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* oauth: Google sign-in button for every accounts.google.com provider, least-privilege gchat default

- AppConnectInner: derive isGoogleSignin from the registry auth_url instead of a
  hardcoded list, so gdocs/gchat/gforms/gcloud/gworkspace get Google's button.
- gchat default scopes: chat.messages is a restricted scope; default to
  chat.spaces.readonly + chat.messages.create (both sensitive). chat.messages /
  chat.messages.readonly stay selectable.
- BRAND_COLORS.md: GchatIcon row in sort order.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 10:42:30 +02:00
Ruben FiszelandClaude Opus 5.5 a8e65ab1e6 fix: lost suspend decrement when concurrent approvals resume a flow (#11450)
* fix: make RunForm schedule props optional and expect 403 for operator drafts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: serialize concurrent approval resumes on the flow's queue row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: read flow status after taking the resume lock

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: route every approval decrement through one helper

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 10:41:25 +02:00
Diego ImbertandClaude Opus 5.5 c0fb2db244 fix: keep flow graph rendered between deploy and navigation (#11454)
* fix: keep flow graph rendered between deploy and navigation

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: rename flow snapshot to avoid shadowing in loadFlow

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 10:39:19 +02:00
Diego ImbertandClaude Opus 5.5 851f6d74c9 fix: ignore edited_at and edited_by in flow and item diffs (#11455)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 10:38:23 +02:00
Ruben FiszelandClaude Opus 5.5 6fe992aebe make RunForm schedule props optional and expect 403 for operator drafts (#11449)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 07:03:53 +02:00
hugocasaandClaude Opus 5 8953ca670a feat: make hub integrations usable as examples in global AI chat (#10599)
* feat: make hub integrations usable as examples in global chat

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: keep web search guidance in sync with provider capability

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: resync web search guidance before the request is built

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: carry loop web search availability into every prompt rebuild

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: drop web search guidance on the completions api fallback

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs: correct onBeforeIteration contract for the fallback re-entry

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* feat: give the ai chat hub script descriptions and integration metadata

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: treat authored hub metadata as evidence the scripts were curated

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: treat hub curated as three-state and speak only for a stated true

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: let the benchmark hub serve integration metadata

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: benchmark the hub tool against a real integration's scripts and metadata

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: cover two more real integrations where the scripts already answer

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: report metadata_source from whether the fixture has authored meta

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: parse the hub resource type schema instead of relaying it as a string

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: match integration suggestions on slug words instead of substrings

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: search the integration a query names outright instead of ranking past it

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: reject hub integration slugs that would re-target the proxied request

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: add a mentioned integration's hits instead of filtering the search to it

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: keep named-integration hits under the content cap and unmangle fixture placeholders

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: cut the middle of a capped hub result instead of repeating its tail

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: cap hub results by keeping the best of the ranked and named hits

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: keep a named integration that ranking placed below the content cap

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: let plan mode use the hub integration lookup

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* feat: mark which hub integrations carry authored provider knowledge

The hub flags the integrations whose document holds hand-written provider
knowledge, so a caller can tell before spending a call on the metadata
endpoint: 18 of ~216 qualify, and for the rest the endpoint returns what
was inferred from the same scripts a search already hands back.

Carry the flag onto search results, where the model first meets a slug, so
get_hub_integration is aimed at the few instead of guessed at. A hub that
predates the flag omits it and nothing is marked.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: stop the documented mark reading as a reason not to call

The flag says the hub additionally holds provider knowledge checked against
the live API. It is not a signal to skip the lookup elsewhere: that call
still returns the resource type and the usage-ranked examples, neither of
which a search result carries, and neither guessable.

The prompt said to read a script instead when the mark is absent, which
traded those for a guess on the ~198 undocumented integrations.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: keep the benchmark's documented flag true to what it serves

The eval hub reported Baremetrics and Holded as undocumented while its
metadata endpoint handed back their authored notes, so a case could teach
the model the flag means nothing. Derive it from both fixture sources, and
pin the agreement.

Also trims the documentedIntegrations comment to the four lines AGENTS.md
allows, keeping the case-folding constraint.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: keep the benchmark hub mostly undocumented, like the real one

Adding holded and baremetrics to the documented set resolved the fixture's
contradiction the wrong way: it left five of six integrations marked, against
the live hub's 18 of ~216, and claimed authored notes for two the hub reports
as having none. Drop the notes instead. Their auth and endpoints are in their
shipped scripts, which is what the cases that use them are about.

Also drops the last two places still describing the flag as a reason to spend
or skip the metadata call.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* refactor: let the model name the integration instead of guessing it from the query

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* refactor: word web search guidance conditionally instead of tracking provider capability

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: open the hub metadata route to job tokens and share one integrations fetch

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: record a copied hub script's source where write_script keeps it

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: pin that a query narrows to the integration it was given

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: match integration suggestions on the name the hub curates

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: name an integration the hub leaves unnamed from the local word table

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-30 20:04:06 +02:00
hugocasaandClaude Opus 5.5 8c7dcbbda5 feat: agents as a standalone kind with home listing, detail and editor pages (#11332)
* feat: list agents on the home page and create them from the new menu

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep runnables out of the agents view and anchor a new agent once saved

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: autosave a new agent's first edit and list agents past one page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: add agent detail and editor pages

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: explain when an agent cannot be run and drop the broken agent move

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep query params and a unique path when creating an agent

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: lead the home list with agents and keep rows while the agent view loads

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: treat a loading agent as undeployed when leaving the editor page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent detail page config panel, run page on form runs, chat badge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent configuration modal and draft paths like other new items

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a new agent draft-free until the first input, land agents with runnables

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: place AI agent after apps in the new menu and describe chat and flow use

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: new agents start with managed memory, editor form says how to turn it off

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clearer managed memory hint in the agent editor form

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: share the agent editor's pane notice as a PaneNotice component

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: name a new agent after a path no resource holds

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: tell repeated tool names apart and hide permissions on draft-only agents

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent configuration beside the model in the chat composer and above the form

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: center the agent run form, configuration beside its Run button

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: icon-only agent configuration button beside Run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agents run on behalf of their deployer through a run-by-path endpoint

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agents keep their run-as identity in their value, preserved by the CLI

The identity an agent runs as lives in `value.on_behalf_of` instead of a column. Every write
of an agent resolves it server-side as a flow's is: the writer's own, unless an admin or
wm_deployers member asks to keep it, and a folder default on create. Retyping a resource into
an agent resolves its value the same way. Export leaves it out; the run endpoint reads it and
drops it from the step's inputs.

The CLI follows the app model: a pushed agent never takes its identity from the tracked file,
an unchanged agent compares equal to the deployed one, and an admin or deployer push claims
the deployed identity back. The owner-change pre-check lists agents.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: deploying an agent draft from review keeps its deployed identity

As for an app: an agent draft carries no identity, so the review page claims the deployed one
back, which the backend honours for an admin or wm_deployers member. The draft diff leaves the
deployed identity out, since a draft never holds one.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: deploying an agent to another workspace offers the run-as choice

An agent deployed to prod/staging, merged from a fork or promoted with `wmill workspace merge`
gets the same identity choice as a flow or an app: the target's current one, the deployer, or
a picked user, sent as a principal the way a trigger's is. The source workspace's principal is
never copied, and a difference in identity alone is not a change in the workspace compare or
its diff.

The frontend consumes the published windmill-utils-internal, so its deploy provider carries the
same rewrite until that version ships.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: agent identity on fork, agent-scoped job reads, and the run license gate

A fork re-points an agent's identity at its creator when they may not preserve someone else's,
and at the creator when it names nobody in the fork, as it does an app's. A token scoped to
`jobs:run:agents:<path>` reads back the runs it starts, chat turns included. The agent run
endpoint checks the enterprise license like every other run entrypoint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: a CLI push decides agent identity handling by the tracked file's type

An agent retyped into another resource by a push kept neither its value's `on_behalf_of` as the
file stated it nor clear of the old agent's identity. The file's type now decides, and only a
deployed agent's identity is claimed back.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: agents run as the caller, with a note on what a shared one needs

Drops the agent run-as identity: its storage in the agent value, the backfill, the resolution
on every write, and its handling in export, the CLI, draft and cross-workspace deploys, forks
and the workspace compare. The run endpoint runs as the caller, so an operator or reader runs an
agent with their own access. The editor tells the author of a folder agent that anyone running
it needs access to its AI resource and to what its tools use.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: agent editor comments describe runs as the caller

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: agent editor pane notes use Alert

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: agent editor pane notes render as Alert

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: agent editor notes as regular Alerts, not banners

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent path as its own editor level, and evals on the agent page

The path leaves the agent form: the editor dialog opens it as a level, as it does evals, and the
editor page in a drawer. The agent page gains Evals, in a dialog. The page supplies the run
form, keeping it out of the editor the flow editor reaches.

The draft edit gate no longer throws when a focused, changed field is removed: the `change` that
removal fires lands mid-teardown, so the gate opens just after instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent settings as the resource editor's header fields, behind a cog

The agent's own settings (path, labels, workspace specific, description) open from a cog as
the flow and script editors' do, laid out as the top of the resource editor. The folder note is
gone.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agent settings fields and cog, completing the rename

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: evals open as a dialog over the agent editor page

The editor page opens an agent's evals over itself, as the agent page does, with the unsaved
edits offered to a run; the editor dialog keeps evals as a level of its own. The two pages share
the dialog.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the unreachable model provider note reads like the unreachable agent one

Same warning level and wording as the note above it, with the path inline rather than in
parentheses that lost their spaces.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the unreachable model provider note offers editing the agent too

Editing the agent to use a provider the reader can access is often the simpler way out; offered
when the reader can write the agent, with Unlink and asking for access.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: provider note lists asking for access as its own option

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: shorter provider note, without the header's buttons repeated

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: evals only for those who can edit the agent

Evaluating builds datasets and runs against the agent, which is authoring: the agent page and the
editor offer it only with write access to the agent.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: agent page actions ordered as the script and flow pages

The menu leads and Edit comes last, as DetailPageHeader lays them out.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the agent editor dialog's levels slide in built on the first visit

Warmed, as the evals pane's levels are, so settings and evals are mounted before the first
navigation rather than inside its transition. Evals are only in the strip where they can be
opened.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the agent's settings report path errors, and hold nothing a reader can edit

The path field reads its error back, so it shows it and keeps deploy blocked on it.
Labels are shown rather than editable without write access. Evals wait for the load
to know they can be opened, and the page layout builds no levels it never shows.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: one builder for an agent's run flow, and the agent page on the shared header

The run endpoint and evals build the agent's one-step flow through the same function.
The agent page uses DetailPageHeader, whose error handler, tag and trigger context are
now optional, and whose menu items keep their disabled state. The home row and the
page share the agent's menu and delete.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the agent page's menu is built from its current path

Deploy settings are the workspace's, so they load once and the menu is derived from
them rather than fetched per path, where a superseded fetch could land after a
navigation. The shared run-flow builder lives with agent runs rather than evals.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: the scoped-read comment names the run-flow builder as it is

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-30 18:40:05 +02:00
ca44043e12 feat: let operators compose flows when the workspace grants the right (#11228)
* feat: let a workspace withdraw operator schedule and trigger writes

Operators can create, edit and delete schedules and triggers today through the
API, CLI and MCP, while the operator_settings flags beside them only hide those
pages. An admin who wants operators to see what is scheduled without letting
them change it cannot express that. Add manage_schedules and manage_triggers as
enforced settings, gated at the schedule handlers and at the generic TriggerCrud
routes so every trigger kind is covered by one check.

They name capabilities operators already hold, so they are granted unless
withdrawn, and absence has to mean "never configured" rather than a value. The
read coalesces to true; the update endpoint merges into the stored jsonb with
the two fields as Option<bool>, so an omitted key keeps what is stored.
operator_settings is git-synced as a whole object, so a settings file written
before these keys existed reaches the endpoint on every pull, and a serde or SQL
default of either polarity would turn that pull into a silent withdrawal or
restoration.

The rights are read through a per-process cache, so withdrawing one publishes a
notify_event that drops the entry on every replica.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4

* feat: let operators compose flows when the workspace grants the right

Adds operator_settings.builder_flows: a workspace setting that lets every
operator compose flows out of runnables that already exist. It does not make
them authors. The boundary the operator role draws is authoring code and running
arbitrary code, and this does not move it: check_flow_is_composition_only walks
the value and refuses anything carrying code, including the shapes an obvious
walk misses (code hoisted into a flow_node, an AI agent step's tools, and a
linked ai_agent resource whose tool list is resolved at run time).

What the walk cannot settle it returns for the caller to authorize under RLS:
the worker tags the steps pin, every runnable they reference, and the (path,
hash) of every version-pinned step. Composing a path is enough to run it and to
run it as whoever it runs as, since the worker resolves a step's path with the
root DB handle and adopts that runnable's on_behalf_of. A pinned hash needs its
own check because dispatch ignores the path beside it.

The gate runs on every write and on both request-supplied-value paths, flow
preview and flow dependencies, or either becomes the way to run what the write
path refuses.

Operators of a builder workspace consume a full author seat; the EE companion
carries the counting.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4

* feat: enforce operator write rights on the router and in the UI

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: close the capture gap and gate the trigger editors' write actions

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: gate acl writes and the native trigger drawer behind manage rights

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: refuse operator writes with 403 and gate sharing at the drawer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* perf: resolve identity in the operator write gate only for writes

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: gate the suspended-jobs actions and stop the route check refusing reads

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: explain the empty-state create button when operator writes are withdrawn

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: audit operator settings changes and fold path writes into native rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: open locked editors read-only and group the operator settings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: skip email and azure lookups on editor open while triggers are locked

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: state each operator-rights rationale once in comments

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: address CI review findings on operator write rights

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep capture move gated and skip it in the builders while locked

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: refuse builder-rights violations with 403 so operators stay logged in

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: trim duplication in the operator builder gates

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: hide build app from builder operators on the flow page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: point at the companion EE PR merged with EE main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a builder's drafts list loading past drafts they cannot write

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: hide saved agents from builder operators in the step picker

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: note the inlined seat rule and drop orphaned sqlx entries

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: stop a builder's step test from logging them out

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: refuse a builder's dependency job on a path it cannot write

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep builders from adding dynamic dropdown code to a flow

A flow's dropdown code runs as whoever loads its form, so a builder may keep or drop the code stored on the flow it updates, never add or change it. The builder's editor hides the dropdown types and code, and previews options through the deployed flow; the inline dropdown refusal is a 403 so it no longer logs operators out. Also trims rationale comments repeated across sites.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: show why saving operator settings failed

The seat-cap refusal on granting builder rights explains what to do; the toast now carries the server's message instead of a generic failure.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: check builder flow drafts like deploys and treat dropdown code as code

A developer who loads a builder's flow draft in the editor runs its dynamic dropdown code as themselves, so a builder's draft now passes the same checks as a deploy. Dropdown code is refused like step code rather than kept or dropped, which also removes the exact-match comparison that refused builders over whitespace.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: bill a builder workspace's operators as developers on cloud

The cloud seat count behind the Premium page, the sidebar usage and the fork cap still weighed every operator at half a seat, while the builder right makes them authors. The out-of-repo invoicing job must follow the same rule.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: check a builder's flow draft as it will be stored

Draft storage strips NUL escapes after the builder check, so a key ending in one (value\u0000, x-windmill-dyn-select-code\u0000) passed the check as an unknown field and was stored under its plain name. The check now reads the sanitized text.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: list a builder's flow drafts and hide hub imports from builders

A builder's undeployed flows now appear in the home list, the flow list and the folder counts. Hub project imports and templates bring scripts and apps along, so builders are no longer offered them. The docs record builders' JavaScript expressions as an accepted risk.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep the stored builder right when a settings payload omits it

A git-synced settings file written before the key existed withdrew the right on every push. builder_flows now follows the manage_* rights: an omitted key leaves the stored value, and the CLI does not count it as a difference.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: word builder refusals by what the flow contains, test the tag refusal

A builder refused on a developer's flow never changed its code, so the refusals now describe the flow ("has inline code, so only a developer can edit this flow") rather than an authoring attempt. The grant confirmation uses the neutral dialog: granting changes billing but destroys nothing. The integration test pins the refusal of a worker tag the workspace cannot use.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: read builder rights from the operating workspace, gate the flow page's audit logs entry

Builder rights now come from useOperatorBuilderFlows(), next to the schedule and trigger locks, so an editor embedded for another workspace answers about that workspace; the legacy AI chat, one instance for the whole app, reads the navigation workspace. The flow page's Audit logs entry follows the operator audit_logs setting now that builders open that menu. Operator settings reset every value on load, null settings included, so nothing carries over from the previous workspace.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: pick a dynamic dropdown's code source by the operating user's role

The flow input editor, the flow test panel and the flow chat send the dropdown request to the operating workspace, so they now also choose inline versus deployed code by the role held there, through useOperatingUser(), instead of the navigation workspace's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 40ac1c5f8cbce3843b582d9b392d3f3cc7eca3e6

This commit updates the EE repository reference after PR #815 was merged in windmill-ee-private.

Previous ee-repo-ref: 31c9e66884b8ca805b20bbfad41fc428fbedbc0e

New ee-repo-ref: 40ac1c5f8cbce3843b582d9b392d3f3cc7eca3e6

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-09-30 18:09:14 +02:00
9613549abc feat: group consecutive tool calls in the AI chat (#11329)
* feat: group consecutive flow edits into one collapsible chat row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: group lookups, name flow steps and fade tool label changes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: count rejected draft saves as failed in tool groups

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: address review nits on chat tool grouping

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: hold a tool group's live step line like its header

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: hold a tool group's live line in the same value as its header

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep main's new tool cards and held calls out of tool groups

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: group app edits and mark single-server MCP groups with the server icon

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: tell MCP servers apart by full path in tool group headers

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a streaming edit in its group and stop rekeying unsettled labels

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: word a queued tool group as settled until a call starts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: give queued tool groups their own wording and leave unnamed calls ungrouped

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a tool group in progress between two of its calls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: treat an edit without a path as unknown unless it is a flow-mode tool

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: let flow mode's pathless edits group again, keep unnamed app edits apart

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: only flow mode's pathless tools default to the open flow

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: key tool rows by their call so a loaded chat never shows a held label

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
2026-09-30 14:05:12 +02:00
GuilhemandClaude Opus 5.5 083db5e388 feat: open chat path pill actions from a hover menu (#11441)
* feat: open chat path pill actions from a hover menu

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: build the path pill menu rows from Button

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: resolve chat path pills by a draft's chosen name

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: alias a draft name only to an item of the same kind

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-30 14:02:38 +02:00
Guilhem 52c31881fc feat: add alert actions and reduce alert padding (#11439)
* style: reduce alert padding

* feat: add alert actions rendered as buttons in the alert's colors

* fix: address review nits on alert actions and button tone

* fix: color split-button outline and divider by tone

* fix: apply tone hover and disabled states to the split-button chevron

* refactor: ignore button tone on split buttons
2026-09-30 14:01:47 +02:00
hugocasaandClaude Opus 5.5 077709b914 feat: rename agent memory options to On and Legacy, explain each (#11442)
* feat: rename agent memory options to On and Legacy, explain each

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: default the chat agent example to On memory and align the schema copy

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: offer Legacy memory only to steps that hold it, explain under the toggle

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: keep the off memory hint true on the saved-agent editor

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: state the 128k fallback in the context window description

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:59:16 +02:00
hugocasaandClaude Opus 5.5 e117871bec weekly ai evals on current models, and claude 5.5/gpt-6 support (#11409)
* feat: run ai evals weekly on current models and post results to a dashboard

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: add current flagship models, a reasoning flag and claude 5.5 defaults

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: never send a reasoning disable claude 5.5 or gpt-6-astra reject, and treat gpt-6 as a reasoning model

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: address review on gpt-6 support, chat completions tools and model metadata

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: leave tiered gpt-6 unpriced and drop the off sentinel on gpt-5 and o-series

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: point the ai_evals readme at the model registry instead of copying it

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor: encode the reasoning rules as per-family maps with a shared parity fixture

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: keep the chat completions tools rule open-ended past gpt-5.6 and scope the parity fixture

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:10:24 +02:00