mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 08:02:19 +00:00
* feat: let a workspace withdraw operator schedule and trigger writes Operators can create, edit and delete schedules and triggers today through the API, CLI and MCP, while the operator_settings flags beside them only hide those pages. An admin who wants operators to see what is scheduled without letting them change it cannot express that. Add manage_schedules and manage_triggers as enforced settings, gated at the schedule handlers and at the generic TriggerCrud routes so every trigger kind is covered by one check. They name capabilities operators already hold, so they are granted unless withdrawn, and absence has to mean "never configured" rather than a value. The read coalesces to true; the update endpoint merges into the stored jsonb with the two fields as Option<bool>, so an omitted key keeps what is stored. operator_settings is git-synced as a whole object, so a settings file written before these keys existed reaches the endpoint on every pull, and a serde or SQL default of either polarity would turn that pull into a silent withdrawal or restoration. The rights are read through a per-process cache, so withdrawing one publishes a notify_event that drops the entry on every replica. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4 * feat: enforce operator write rights on the router and in the UI Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: close the capture gap and gate the trigger editors' write actions Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: gate acl writes and the native trigger drawer behind manage rights Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: refuse operator writes with 403 and gate sharing at the drawer Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * perf: resolve identity in the operator write gate only for writes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: gate the suspended-jobs actions and stop the route check refusing reads Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: explain the empty-state create button when operator writes are withdrawn Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: audit operator settings changes and fold path writes into native rows Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: open locked editors read-only and group the operator settings Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: skip email and azure lookups on editor open while triggers are locked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs: state each operator-rights rationale once in comments Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: address CI review findings on operator write rights Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep capture move gated and skip it in the builders while locked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep admin and operator exclusive when setting a workspace role Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * refactor: use the shared section component for operator settings groups Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
49 lines
1.6 KiB
Rust
49 lines
1.6 KiB
Rust
/*!
|
|
* The integration tests clear the rights cache in-process, so they pass whether or not this
|
|
* trigger fires. Only the emitting half is covered here: `process_notify_event` lives in the
|
|
* server binary.
|
|
*/
|
|
|
|
use sqlx::{Pool, Postgres};
|
|
|
|
const WS: &str = "test-workspace";
|
|
|
|
async fn emitted_payloads(db: &Pool<Postgres>) -> Vec<String> {
|
|
sqlx::query_scalar::<_, String>(
|
|
"SELECT payload FROM notify_event WHERE channel = 'notify_operator_settings_change'",
|
|
)
|
|
.fetch_all(db)
|
|
.await
|
|
.expect("read notify events")
|
|
}
|
|
|
|
async fn set_operator_settings(db: &Pool<Postgres>, settings: &str) {
|
|
sqlx::query(
|
|
"UPDATE workspace_settings SET operator_settings = $2::jsonb WHERE workspace_id = $1",
|
|
)
|
|
.bind(WS)
|
|
.bind(settings)
|
|
.execute(db)
|
|
.await
|
|
.expect("update operator settings");
|
|
}
|
|
|
|
#[sqlx::test(migrations = "../migrations", fixtures("base"))]
|
|
async fn withdrawing_a_right_emits_the_cache_invalidation(db: Pool<Postgres>) {
|
|
set_operator_settings(&db, r#"{"manage_schedules": false}"#).await;
|
|
assert_eq!(
|
|
emitted_payloads(&db).await,
|
|
vec![WS.to_string()],
|
|
"the payload must be the workspace id: `process_notify_event` invalidates by it"
|
|
);
|
|
|
|
// Rewriting the same settings must stay silent, or every unrelated save of the settings row
|
|
// would drop the entry on every replica and send them all back to the database.
|
|
set_operator_settings(&db, r#"{"manage_schedules": false}"#).await;
|
|
assert_eq!(
|
|
emitted_payloads(&db).await.len(),
|
|
1,
|
|
"an update that leaves operator_settings unchanged must not emit"
|
|
);
|
|
}
|