mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-19 08:01:25 +00:00
f481ea4059b4e5cb01273cffeb53ff340e8bd5bd
6 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f2be625348 |
feat: store hashed tokens instead of plaintext (#8217)
* feat: store hashed tokens in the token table instead of plaintext
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: address review issues in token hash migration
- Update all base.sql fixtures to include token_hash/token_prefix columns
- Keep plaintext token for webhook tokens (needed for URL reconstruction)
- Restore get_token_by_prefix to query DB for webhook tokens
- Fix down migration to delete NULL-token rows before restoring NOT NULL
- Update parser fixture standalone schema
- Update EE dedicated_worker_ee.rs to use token_hash/token_prefix
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: restore sqlx offline cache (only add new query files)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: keep writing plaintext token column for backward compat
Write to token column alongside token_hash until MIN_VERSION_SUPPORTS_TOKEN_HASH
(1.649.0) is reached. This ensures older workers can still authenticate
during rolling upgrades. Remove the separate UPDATE in new_webhook_token
since create_token_internal now writes plaintext directly.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: branch on MIN_VERSION to write plaintext token or null
Check MIN_VERSION_SUPPORTS_TOKEN_HASH at runtime: write plaintext to
token column while old workers exist, switch to NULL once all workers
are >= 1.649.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: set MIN_VERSION_SUPPORTS_TOKEN_HASH to 1.650.0
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use token_hash for email lookup and expiry notifications
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: rotate webhook tokens instead of recovering plaintext from DB
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: use token_hash for native trigger token lookups and deletes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* sqlx
* refactor: drop webhook_token_prefix from native_trigger table
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: backward compat for token rotation and make webhook_token_hash NOT NULL
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: prevent panic on short superadmin secret token prefix
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: prevent panic on short superadmin secret token prefix
Replace all `token[0..TOKEN_PREFIX_LEN]` slicing with
`token.get(..TOKEN_PREFIX_LEN).unwrap_or(token)` to prevent
panics when a token shorter than 10 chars is provided (e.g.
malformed Authorization header, short superadmin secret).
Co-authored-by: hugocasa <hugocasa@users.noreply.github.com>
* fix: prevent panic on short token prefix slicing
Replace all `token[0..TOKEN_PREFIX_LEN]` with safe
`token.get(..TOKEN_PREFIX_LEN).unwrap_or(token)` to prevent panics
on malformed tokens shorter than 10 characters.
Co-authored-by: hugocasa <hugocasa@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Revert "fix: prevent panic on short superadmin secret token prefix"
This reverts commit
|
||
|
|
83be59e0e8 |
fix: debounce webhook arg accumulation with max_count/max_time limits (#8307)
* fix: correct debounce max_total_debounces_amount semantics and complete previous job on limit exceeded Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: enable debounce arg accumulation for post-preprocessing flows Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add debounce accumulation tests for max_count and max_time limits Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test: add push-time max_count and max_time accumulation tests Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * sqlx * sqlx --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
438f609a78 |
fix: delete debounce_key on post-preprocessing limit exceeded (#8299)
* fix: delete debounce_key entry when post-preprocessing limits exceeded For preprocessor flows, the runnable_settings_handle has debounce_delay_s = None, so maybe_apply_debouncing at pull-time won't clean up stale debounce_key entries. Previously we only reset the entry (UPDATE), but since the flow executes immediately without rescheduling, a stale entry would cause the next incoming flow to incorrectly try to debounce against an already-executing job. Change from UPDATE (reset) to DELETE so the entry is fully removed. Update tests to expect deletion instead of reset. Companion EE PR: https://github.com/windmill-labs/windmill-ee-private/pull/448 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: persist accumulated debounce args to v2_job for flows The in-memory arg accumulation in maybe_apply_debouncing was not persisted back to v2_job. For scripts this is fine (single execution), but for flows, subsequent steps re-read args from the DB via get_mini_pulled_job and would see the original (non-accumulated) value. Also improve the job log message to show both original and accumulated argument values for clarity. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: update ee-repo-ref to d1c14355026151ecdd31adda8e2c60ecd1b5ad65 This commit updates the EE repository reference after PR #448 was merged in windmill-ee-private. Previous ee-repo-ref: bff784002a3335af7c10982599c8f03e536d5abf New ee-repo-ref: d1c14355026151ecdd31adda8e2c60ecd1b5ad65 Automated by sync-ee-ref workflow. * test: assert accumulated debounce args are persisted to v2_job Add DB persistence assertions to accumulation tests to prevent regressions on the fix that writes accumulated args back to v2_job. Without this, flow steps re-reading args from the DB would see the original (non-accumulated) value. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * sqlx * chore: update ee-repo-ref.txt to ee-private main Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com> |
||
|
|
9e92445fae |
fix: preserve debouncing settings for post-preprocessing arg accumulation (#8191)
* fix: preserve debouncing settings for post-preprocessing arg accumulation After preprocessing completes, store the flow's debouncing settings in runnable_settings_handle on v2_job_queue so that maybe_apply_debouncing can find them when the surviving job is pulled. Without this, the handle is NULL and arg accumulation silently does nothing for flows with preprocessors. Also adds a debouncing badge in flow settings and 4 focused accumulation tests covering scripts, flows without preprocessor, flows with preprocessor (with and without the fix). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: update sqlx prepared query for worker_flow.rs change Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
a00927b300 |
fix: preserve debouncing settings for flows with preprocessors (#8043)
* fix: preserve debouncing settings for flows with preprocessors
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Revert "fix: preserve debouncing settings for flows with preprocessors"
This reverts commit
|
||
|
|
ea52a8b8ce |
refactor: move integration tests to subcrates to reduce recompilation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |