mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-09 08:03:50 +00:00
Postgres roles are cluster-wide, so two data tables that generate one name share a login. The name's discriminator was four bytes, which is searchable rather than merely unlucky: two data table names that collide were found by hand. It is now sixteen, and a name that is already taken is refused unless this data table owns the role (enterprise repo). The database a data table's roles were created in is recorded with them and checked where the connection is finally resolved. The guards that refuse a resource edit read the config separately from the save that enables permissions, and never expand a `$res:` or `$var:` that can repoint the resource just as well — so they stay as early refusals while the check that holds is the one at the point of use. Dropping a deleted data table's roles now runs after the settings transaction commits, planned before it: `DROP OWNED` discards their grants for good, and a save that rolls back after that point would leave a data table naming logins that no longer exist. Leaving a workspace takes the tenant of the row it deletes rather than of the cached identity, which a rename leaves stale, and group deletion takes the settings row before the membership rows like every other path that frees a principal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01S5arH3G2Sa1Qqm32veJQ1n