* fix(mcp): use computed base_internal_url instead of static default
Pass the actual base_internal_url (computed from the runtime port) to
the MCP backend instead of using the static BASE_INTERNAL_URL which
defaults to http://localhost:8000. This fixes internal API calls when
the server runs on a non-default port.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix
* remove BASE_INTERNAL_URL
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Add LOGIN_DOMAIN environment variable that appends a domain to emails
missing one during external login (OAuth/SAML/SCIM). When set, emails
without '@' will have '@{LOGIN_DOMAIN}' appended.
Example: LOGIN_DOMAIN=example.com transforms "john" to "john@example.com"
Also includes a migration to lowercase existing emails in critical tables:
- password (primary user identity)
- usr (workspace users)
- email_to_igroup (instance group memberships)
- token (active sessions)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Add tests verifying the interaction between instance groups and workspace
auto-add functionality:
- Users in instance groups get auto-added to configured workspaces
- Role assignment (admin/operator/developer) works correctly
- Role precedence when user belongs to multiple groups
- User removal when removed from instance group
- Cleanup when instance groups removed from workspace config
- added_via field tracking
Tests are ignored by default in CI and can be run locally with:
cargo test -p windmill --test instance_group_auto_add --features private,enterprise -- --ignored
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* check endpoint
* use flag for cred check on worker
* use sdk for auth chat side
* cleaning
* cleaning
* also handle GET
* Add session token support in BedrockClient::from_credentials
Users with temporary STS credentials need session tokens for AWS
authentication. This adds the optional session_token parameter to
support these use cases.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Cache AWS SDK config loading to avoid repeated I/O
aws_config::load_defaults() performs environment variable lookups and
potentially file I/O on each call. Cache the result in a static OnceCell
to improve performance on high-frequency Bedrock requests.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Add debouncing to Bedrock credential check button
Prevent rapid clicks from spawning multiple concurrent flow preview
jobs for the worker credential check.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove orphaned SigV4 signing comment
The manual SigV4 signing code was removed in favor of the AWS SDK,
but this documentation comment was left behind.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove verbose tracing info and change-related comments
- Remove per-request auth method info logs (too verbose for production)
- Simplify from_env log to single debug-level message
- Remove comments describing future changes rather than current behavior
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* cleaning
* Fix Bedrock feature flag compilation warnings
Gate AWS-specific imports, struct fields, and methods behind the bedrock
feature flag to eliminate dead code warnings when building without the
bedrock feature enabled.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* bedrock flag
* cleaning
* Move BedrockCredentialsCheck from edit drawer to add drawer
The component was incorrectly shown when editing resources instead of
when adding new ones. Moved it from ResourceEditor.svelte to
ApiConnectForm.svelte.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* cleaning
* cleaning
* make aws-config optional
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Renamed deprecated type aliases following rmcp library update:
- CallToolRequestParam → CallToolRequestParams
- InitializeRequestParam → InitializeRequestParams
- PaginatedRequestParam → PaginatedRequestParams
Also added required `meta` field to ClientInfo and CallToolRequestParams.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Convert to Svelte 5 syntax with $props(), $bindable(), $derived()
- Add $derived() to recompute date when value changes externally
- Handle empty string dateFormat by falling back to default
- Remove sendUserToast from derived computation (caused state mutation error)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
SERVER_BIND_ADDR now works for both server and worker modes with
different defaults: 0.0.0.0 for server/indexer/mcp, 127.0.0.1 for workers.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The toggle states are now saved to localStorage and restored when
navigating back to the runs page, providing a consistent user experience.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add permissions test suite covering scripts, flows, apps, resources,
variables, schedules, and folder-based permissions
- Add test for operator restrictions (cannot create/update/archive)
- Restrict operators from archiving scripts (archive_script_by_path,
archive_script_by_hash) for security consistency with flows/apps
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>