15023 Commits
Author SHA1 Message Date
Ruben Fiszelandrubenfiszel 14d2995d76 chore(main): release 1.823.0 (#11503)
* chore(main): release 1.823.0

* Apply automatic changes

---------

Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com>
v1.823.0
2026-10-04 14:11:48 +02:00
Ruben FiszelandClaude Opus 5.5 26856b8061 fix: cancel an abandoned pg query and close failed connections cleanly (#11511)
* fix: cancel the query of a timed out or cancelled postgresql job

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* test: fail the cancelled-query test unless the cancel happened

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* fix: leave a failed pg job's connection clean for a pooler before closing it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* fix: cancel a failed pg job's unread results and roll back only inside a transaction

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* fix: redo a pg connection's closing reset when a late cancel lands on it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* fix: let a late cancel land on the settle query without skipping the reset

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-04 14:04:24 +02:00
Ruben FiszelandClaude Opus 5.5 33f6de0cd2 fix: apply the pg keepalive settings to the postgres trigger connection (#11512)
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-04 11:41:12 +02:00
Ruben FiszelandClaude Opus 5.5 711e08c1d2 fix: bound the datatable migration lock wait and reap a dead holder (#11510)
* fix: bound the datatable migration lock wait and reap its dead holder

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

* docs: say what the migration lock keepalives cover behind a pooler

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-04 11:40:20 +02:00
Ruben FiszelandClaude Opus 5.5 fa419af9b3 fix: drop a fork's datatable database despite connected sessions (#11509)
Claude-Session: https://claude.ai/code/session_019cpWeGy8jRMtWqvuRBpgu4

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-04 08:55:30 +02:00
GuilhemandClaude Opus 5.5 35ec16d127 fix: delete a flow chat turn with its flow run, not its step jobs (#11477)
* fix: delete a flow chat turn with its flow run, not its step jobs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: give flow-written answers and overlapping turns their own flow run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 20:19:06 +02:00
GuilhemandClaude Opus 5.5 0f65df24d2 feat: redesign the service logs page (#11506)
* feat: redesign the service logs page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: drop a stale jump after a cached host switch and remove unused max_lines

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep focus on url sync and expose host selection and new logs to assistive tech

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: reset the tail on dropdown host picks, resume refresh after search, key log cache by host

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clear the pending jump when a host switch needs no fetch

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 20:18:44 +02:00
Ruben FiszelandClaude Opus 5.5 d4a423f567 fix: bound the pg cached-connection reset probe so a vanished server fails fast (#11505)
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 11:14:36 +02:00
Ruben Fiszelandrubenfiszel 3c30c82fa2 chore(main): release 1.822.0 (#11480)
* chore(main): release 1.822.0

* Apply automatic changes

---------

Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com>
v1.822.0
2026-10-03 09:42:45 +02:00
GuilhemandClaude Opus 5.5 64f9505688 feat: show upcoming events when hovering a schedule's cron expression (#11499)
* feat: show upcoming events when hovering a schedule's cron expression

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: read cron version from the draft for draft-only schedule previews

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:42:21 +02:00
Ruben FiszelandClaude Opus 5.5 0eb6320faa test: make the import refusal reach the handler guard (#11502)
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:42:09 +02:00
Ruben FiszelandClaude Opus 5.5 013b302d48 perf: keep a pg executor connection per database (#11492)
* fix: stop the pg executor cache from pinning a pooler slot

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test: retry while the evicted pg backend exits

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf: keep a pg executor connection per database

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: close a pg connection whose query was cut off by a timeout or cancel

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: keep a pg connection only after its query read every result

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: free idle pg connections and retry when a connect is refused

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: retry a pg connect only when a connection cap refused it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: detect pg connection caps by SQLSTATE and label cloud connections as new

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:34:10 +02:00
e7fc1b2e2e feat: restricted job tokens per script and flow (#11484)
* feat: restricted job tokens (job_token_scopes on scripts and flows)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: admit flow-run reads, skip dedicated workers, gate on worker version

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep restricted jobs off flow runners, preserve scopes on rename and promotion

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep restricted jobs off every dedicated handoff, confine progress flow id

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: exclude restricted runnables from dedicated worker startup

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: gate restrictions on the release after 1.821.0

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: store per-job scopes on job_perms instead of v2_job, pin inline runs to the checked version

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: step-level job_token_scopes for flow steps and agent tools

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: fail closed on perms read errors, refuse restricted queue imports, gate step scopes in previews

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: carry a job's scopes on its completion so a re-run keeps the caller's cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: carry a zombie job's scopes into its completion

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: leave a zombie for the next sweep when its scopes cannot be read

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* docs: correct the QueuedJobV2 completion comment

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: validate step scopes in batch flows, fail closed on unvalidated step scopes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: refuse flows with step or tool restrictions at push while an older worker is live

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: apply the step-scope worker gate to flow restarts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: list the job token toggle with the other step and flow settings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* chore: pin the EE companion merged with EE main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* perf: skip scope lookups for unrestricted jobs; list job token setting last

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* style: rustfmt scopes tests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* fix: confine restricted job tokens to their own run lineage; drop remaining extra lookups

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014FHGE3ynoAu6yrgeg4kLwL

* chore: update ee-repo-ref to 259ad3bfeef5285ba80eedc86309b11dca001220

This commit updates the EE repository reference after PR #843 was merged in windmill-ee-private.

Previous ee-repo-ref: 2b77c0225dca441235daf7bf0a06ba968df0c927

New ee-repo-ref: 259ad3bfeef5285ba80eedc86309b11dca001220

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-03 09:33:44 +02:00
Ruben Fiszel e952298f84 feat: replace the AI input filling toggle with an additional prompt (#11501)
* feat: replace the AI input filling toggle with an additional prompt for AI

* feat: pass the additional prompt for AI to MCP clients and shared AI guidance

* feat: shrink the run page AI card to a button and a collapsed prompt

* fix: offer writers a way to add a prompt for AI from the run page
2026-10-03 09:33:18 +02:00
Ruben FiszelandClaude Opus 5.5 b7f74cd562 fix: never reuse a pg connection a script left inside a transaction (#11497)
* fix: never reuse a pg connection a script left inside a transaction

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: close a pg connection whose job failed instead of caching it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* docs: describe every caller of PgConnectionLease::discard

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:03:44 +02:00
Ruben FiszelandClaude Opus 5.5 f2393e5b24 keep flow priority input inline with its toggle on wide screens (#11500)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 09:00:32 +02:00
Ruben FiszelandClaude Opus 5.5 68f8f19b33 fix: keep a resource default set in the schema when the script is redeployed (#11495)
* fix: keep a resource default set in the schema when the script is redeployed

Fixes #11493

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a schema resource default only while the arg stays that resource type

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: drop a scalar resource default when the arg becomes a list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 08:57:04 +02:00
Ruben FiszelandClaude Opus 5.5 d7227726be feat: log pg job progress, warn on stalls, detect dead db connections (#11491)
* feat: log pg job progress, warn on stalls, detect dead db connections

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: log only slow pg steps to keep job log writes off fast statements

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

* fix: say when a slow connect included a failed cached-connection reset

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KHjj2iG8kKPCaFuK6bqXvi

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 22:26:37 +02:00
Ruben FiszelandClaude Opus 5.5 eed7e7d9e6 fix: stop the pg executor cache from pinning a pooler slot (#11490)
* fix: stop the pg executor cache from pinning a pooler slot

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test: retry while the evicted pg backend exits

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 22:21:58 +02:00
d949484e7b feat: read the OIDC signing key from a file and rotate it (#11482)
* feat: read the OIDC signing key from a file and rotate it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: bump ee ref

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rmQBQKBgsrd4dJ55vv8n5

* chore: update ee-repo-ref to fe47a306d3760ac2d5a8e14365f05a3503a3ac35

This commit updates the EE repository reference after PR #841 was merged in windmill-ee-private.

Previous ee-repo-ref: 7bd97ee7ce32188a171df9190af990d84586752b

New ee-repo-ref: fe47a306d3760ac2d5a8e14365f05a3503a3ac35

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 22:18:32 +02:00
99e96d3f78 fix: let instances withhold signing secrets from the settings API (#11483)
* fix: never return the instance signing secrets from the settings API

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: tell wmill instance get-config users that jwt_secret is not exported

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: point ee-repo-ref at the oidc signing key fix

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: block rsa_keys from agent workers and keep get-config stdout pure yaml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep server secrets in exports by default behind EXPORT_SERVER_SECRETS

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 43b2ce8866a393b2666b17647ddb1466afc70bb1

This commit updates the EE repository reference after PR #842 was merged in windmill-ee-private.

Previous ee-repo-ref: 3a0d0c3f45eeb9f5fe8d50ce3798239aa9101a22

New ee-repo-ref: 43b2ce8866a393b2666b17647ddb1466afc70bb1

Automated by sync-ee-ref workflow.

* fix: withhold server secrets on any non-true EXPORT_SERVER_SECRETS value

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 19:25:04 +02:00
Ruben FiszelandClaude Opus 5.5 98274a7336 fix: let legacy draft-only items be discarded from the home page (#11488)
* fix: let legacy draft-only items be discarded from the home page

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: describe the legacy draft move guard as it now is

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 19:11:50 +02:00
Ruben FiszelandClaude Opus 5.5 920771b598 keep tagged binary prebuilds off the dependency job tag (#11489)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 19:07:50 +02:00
4beb1f9420 feat: add trigger, tag, run-as and digest claims to job OIDC tokens (#11481)
* feat: add trigger, tag, run-as and digest claims to job OIDC tokens

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: parse digest floats exactly and derive the codebase digest like push

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: give flows that reference flow nodes no digest and keep --json clean

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: list flow step digests from module positions only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test: skip the pulled module-script digest check on windows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 71b8c1042fd8188c2d2882476f12b671cb5ba421

This commit updates the EE repository reference after PR #840 was merged in windmill-ee-private.

Previous ee-repo-ref: ba1870536789a43c5b6ec18522a93edb9cb07f3d

New ee-repo-ref: 71b8c1042fd8188c2d2882476f12b671cb5ba421

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-02 19:02:17 +02:00
Ruben FiszelandClaude Opus 5.5 4bc7e0d7ba feat: add a cancel-only jobs:cancel token scope, optionally path-scoped (#11479)
* feat: add a cancel-only jobs:cancel token scope, optionally path-scoped

jobs:cancel grants the four cancel routes (cancel, force cancel, cancel
selection, cancel persistent) and nothing else; jobs:write keeps covering
them. With paths, the handlers only cancel a job whose own runnable path,
or a parent flow's, matches; others get the invisible-job NotFound.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: confine cancel_selection like the by-id cancel routes

A token that also carries a path-scoped jobs:run scope is confined to
those runnables on the by-id cancels (through the job read check), so
apply the same run confinement to each selected job.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: confine persistent cancels, admit agent runs, batch selection checks

cancel_persistent applies the run-scope confinement the other cancel routes
apply; a path-scoped jobs:cancel admits agent runs under the agent's path,
recognized as the run-scope read check does; cancel_selection checks the
cancel scope in one query.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: let a jobs:cancel grant stand on its own on the cancel routes

Intersecting cancels with the token's jobs:run scopes did not hold: the
token could mint itself a child carrying only the cancel scope. The cancel
routes now apply the cancel paths and the usual per-job visibility, and
leave the run-scope read confinement to reads, as jobs:write does.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 18:59:37 +02:00
Ruben FiszelandClaude Opus 5.5 3d1d249556 feat: add an instance setting routing all dependency jobs to one tag (#11486)
* feat: add an instance setting routing all dependency jobs to one tag

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep bunnative locks on bun and explain the default dependency routing

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 18:40:32 +02:00
Ruben FiszelandClaude Opus 5.5 14801fdd68 fix: unstick postgres jobs on large results with custom-typed columns (#11475)
* fix: unstick postgres jobs on large results with custom-typed columns

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: carry the parked-rows delivery fix in the postgres fork

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: describe postgres queries before streaming instead of parking rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf: skip the postgres describe for statements that return no rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: look for returning in the whole postgres statement

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: read the leading postgres keyword past nested block comments

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: end leading postgres line comments at CR too

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 17:21:20 +02:00
Ruben FiszelandClaude Opus 5.5 ae093b7666 fix: read inet and cidr results with their prefix, including arrays (#11476)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 15:56:11 +02:00
Ruben Fiszelandrubenfiszel fee401f01e chore(main): release 1.821.0 (#11432)
* chore(main): release 1.821.0

* Apply automatic changes

---------

Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com>
v1.821.0
2026-10-01 18:35:57 +02:00
hugocasaandClaude Opus 5.5 64f0e87d57 oauth: add github scope_options (gist, read:org) (#11471)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:35:44 +02:00
153b02a5de fix: offer user scopes in the slack scope editor and drop the generated description on type change (#11464)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
2026-10-01 18:31:23 +02:00
hugocasaandClaude Opus 5.5 f74113c75a post ai eval results to the workspace-prefixed cloud route (#11473)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:26:34 +02:00
Diego Imbert 26be1d7da8 feat: add test key button to AI resource drawers (#11466)
* feat: add test key button to AI resource drawers

* fix: scope-check inline AI resource values and keep test model editable

* fix: keep test model editable for unsaved resources, own-key provider check
2026-10-01 18:25:49 +02:00
GuilhemandClaude Opus 5.5 88d0cd00e5 fix: restore the save to workspace button on inline flow steps (#11469)
* fix: restore the save to workspace button on inline flow steps

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: make the inline step save to workspace button icon only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 18:25:25 +02:00
hugocasaandClaude Opus 5.5 7f1beadf79 feat: add wmill datatable migrate status (#11465)
* feat: add wmill datatable migrate status

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: show unpushed local migrations in datatable migrate status

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: move pushLocalMigrations doc comment back onto its function

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:22:04 +02:00
hugocasaandClaude Opus 5.5 c72ae8f7d4 oauth: offer granular gcal read scopes (calendar list, metadata, free/busy) (#11459)
Keeps the calendar.events default. Adds calendarlist.readonly, calendars.readonly
and freebusy as labelled scope_options so the hub's get_calendar_list,
get_calendar_metadata and free/busy scripts can be granted least-privilege.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:21:52 +02:00
hugocasaandClaude Opus 5.5 ab2de838d7 feat: offer slack write scopes as bot and user scope options (#11472)
* fix: offer user scopes in the slack scope editor and drop the generated description on type change

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: offer slack write scopes as bot and user scope options

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 18:20:36 +02:00
Ruben FiszelandClaude Opus 5.5 8c92e63ffc chore(docker): bump bundled crane to v0.22.1 (#11470)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 18:17:55 +02:00
Ruben FiszelandClaude Opus 5.5 1c6758a656 fix(npm-proxy): support _auth and username/_password basic auth from npmrc (#11467)
* fix: send npmrc basic auth (_auth, username/_password) from the npm proxy

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: resolve npmrc credentials from parent paths like npm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: honor empty npmrc overrides and keep registry credentials to its origin

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 17:52:47 +02:00
GuilhemandClaude Opus 5 b10f83c763 feat(sessions): show an item's deployed page in the preview panel (#11458)
* feat(sessions): show an item's deployed page in the preview panel

The preview panel showed an item's editor and nothing else. It now shows the
deployed page too, as a tab of its own.

**Two sides, two tabs.** The editor and the deployed page are different things
to look at, so `isItemTabFor` keys on the side rather than the item: asking for
a side already open focuses it, asking for the other opens it alongside. Two
editors for one item still cannot coexist — they would race its single
(kind, path) cell — but an editor beside a viewer is safe, since the viewer
reads the deployed version over the API and holds no cell. The tab breadcrumb
keeps re-pointing in place; `Exit & see details` and the detail page's `Edit`
open the other side instead of consuming the one you are on. A tab's label
carries `(edit)` when it is the editor side.

**The detail pages moved out of their routes.** `/scripts/get` and `/flows/get`
are now thin wrappers over `ScriptDetail` and `FlowDetail`, which the panel
renders too. Everything they reach — drawers, triggers, saved inputs — is scoped
to the viewer's workspace through `setOperatingWorkspace`, and every navigation
they attempt is caught by `interceptNav` and turned into a move inside the
panel, so nothing takes the browser out of the session. A plain click is
intercepted; ⌘-click and middle-click still open a real tab, which is why the
pages keep their `href`s.

**The picker opens what exists.** A row opens the deployed page, or the editor
when nothing is deployed there, and carries a Draft / Draft only badge in the
review dock's words. `WorkspaceItem` gained `draftOnly` and `hasDraft` from the
listers, which already returned both; deploys now invalidate the picker cache
through `itemDeployed`, so a just-deployed item stops reading as a draft. Rows
also carry a hover Edit action, reachable from the keyboard with the pick
modifier.

`open_preview` gained a `mode`, narrowed out of the advertised schema for a
session that cannot write drafts and re-checked per path in the handler, where
a refusal reports "couldn't check" apart from "denied". The mode is resolved
before those checks, so a call that omits it is gated as the editor it will
become.

Alongside, the workspace a detail page acts on is now the one it is showing
rather than the one the browser is navigated to: `MoveDrawer`,
`toggleWorkspaceErrorHandler` and the pages' own permission gates read the
operating workspace and its acting user, and `RunForm` mints a password
argument's ephemeral variable there too — in a fork session all of these
previously answered for the parent. `InWorkspaceAppViewer` hands the app's
`ctx` user down as a prop instead of writing the global `userStore`, which from
a session tab was re-pointing every permission check on the page.

Fixes found on the way: `DetailPageLayout` claimed `h-screen` inside a panel
that is not the viewport; Edit on a historical script version dropped the
version from the intercepted click; the Run button stayed spinning after a run
that left the page mounted; and the window-level run shortcut fired from a
collapsed panel and from keys another handler had already claimed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(sessions): historical edits, stale not-found, shared edit rights, tab labels

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep deployed-page links and workspace reads in the session

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): scope detail hrefs to the session, re-point the viewer's own tab

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep a previewed raw app's route out of the session URL

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): resolve edit-in-fork against the session workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): read advanced run tags from the session workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): fork from the session workspace, star only navigation items

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): mount only the side a preview tab shows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): address CI review round 1 findings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): route links in a deployed page's drawers through the panel

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): tell the chat which deployed page the panel shows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): only a 404 reads as an undeployed raw app

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): scope the unparseable-JSON run gate to the form

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): a flow deleted from the panel stays in its tab

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): the picker's edit shortcut works on the current row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): load-error toasts say what failed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(sessions): keep an oversized invalid JSON editor in its form's run gate

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* revert: keep main's draft_only description in openapi.yaml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-10-01 17:43:52 +02:00
d518aa5557 feat: let slack connects issue a user token via user_scope (#11452)
* feat: let slack connects issue a user token via user_scope

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: keep trailing newline in ee-repo-ref

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: bump ee-repo-ref

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: name the provider in slack token descriptions and refresh them on reconnect

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: drop the generated slack description when connecting another provider

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: drop the slack scope pin migration, slack ignores scope on refresh

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: clear the generated slack description on client-credentials connects too

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: update ee-repo-ref to ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7

This commit updates the EE repository reference after PR #837 was merged in windmill-ee-private.

Previous ee-repo-ref: 83298dcf23574d5ed05e6c767bf1d9b067ab7a95

New ee-repo-ref: ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-01 14:53:22 +02:00
227e934210 feat: harden job OIDC tokens with version claims, jti and a lifetime cap (#11457)
* feat: harden job OIDC tokens with version claims, jti and a lifetime cap

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: count restarted flow nodes as latest only if the current version uses them

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: follow stored loop and branch bodies when resolving current flow nodes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: bind current flow nodes to their step id and skip non-numeric node keys

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: derive flow step currency from the flow above it and restarts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: treat every restarted job but a version-checked flow as not latest

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: count a restarted body as latest when the run it came from was current

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to b469efc9ceddfaaa1040e4cb2c18993822f92c78

This commit updates the EE repository reference after PR #838 was merged in windmill-ee-private.

Previous ee-repo-ref: 25e0b9ae1c6c60419a479fa38d5dc5928832790a

New ee-repo-ref: b469efc9ceddfaaa1040e4cb2c18993822f92c78

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-10-01 14:09:36 +02:00
Ruben FiszelandClaude Opus 5.5 d2830cb4a0 fix: stop running deleted script versions from worker caches (#11456)
* fix: stop running deleted script versions from worker caches

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: reuse script cache invalidate and test the deletion notify payload

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: keep a deleted copy from shadowing the same hash in another workspace

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: drop deletions missed while down and fills racing the eviction

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: batch deletion events, evict path caches and cover version pruning

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: evict the raw-import cache on both passes and split large deletion events

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 13:37:00 +02:00
hugocasaandClaude Opus 5.5 840567fbe5 feat: labelled scope checkboxes in the oauth connect dialog (#11460)
* feat: show human labels for oauth scope options in the connect dialog

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: always show scope checkboxes, label gdocs and gchat scopes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat: offer default scopes as checkboxes for every oauth provider

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 13:29:02 +02:00
GuilhemandClaude Opus 5.5 ddde41bc1d fix: block runs while a JSON input does not parse (#11463)
* fix: block runs while a JSON input does not parse

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clear json editor error on unmount and flush editors before run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: restore validity when a nullable arg input is cleared

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: let field editors parse before the run check and reset the message on view switch

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: clear the run refusal message when form validity changes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 13:28:41 +02:00
Ruben FiszelandClaude Opus 5.5 5bd2c2c254 drop unused mut that breaks the backend integration test build (#11462)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 11:13:45 +02:00
Ruben Fiszel f1d970bd1a ci: move CI AI models to opus 5.5, gpt-6.1 sol and deepseek v4.1 (#11461)
* ci: move CI AI models to opus 5.5, gpt-6 and deepseek v4.1 flash

* test: point the deepseek eval alias at v4.1 flash

* ci: run the codex review on gpt-6.1-sol with codex cli 0.159.3
2026-10-01 11:11:57 +02:00
dependabot[bot] 94924d4644 chore(deps): bump docker/build-push-action from 5 to 7 (#11421)
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 5 to 7.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/v5...v7)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 10:49:45 +02:00
Ruben FiszelandClaude Opus 5.5 c25bb1ed90 feat: add //no_network annotation for native scripts (#11445)
* feat: add //no_network annotation to deny all network access in native scripts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: close no_network bypasses (quic dns, header parsing, token, non-native)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: refuse //no_network on deno regardless of //native, derive disabled ops from deno_net

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: scope //no_network to native scripts only, drop bun/deno refusal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 10:47:28 +02:00
hugocasaandClaude Opus 5.5 bba58c4167 oauth: add gdocs and gchat providers (#11447)
* oauth: add gdocs and gchat providers, gchat icon

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* oauth: Google sign-in button for every accounts.google.com provider, least-privilege gchat default

- AppConnectInner: derive isGoogleSignin from the registry auth_url instead of a
  hardcoded list, so gdocs/gchat/gforms/gcloud/gworkspace get Google's button.
- gchat default scopes: chat.messages is a restricted scope; default to
  chat.spaces.readonly + chat.messages.create (both sensitive). chat.messages /
  chat.messages.readonly stay selectable.
- BRAND_COLORS.md: GchatIcon row in sort order.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 10:42:30 +02:00