mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 16:02:12 +00:00
* feat(datatables): add an ACL editor for data table roles Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: take every pooled connection before the ACL apply locks Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: refresh grant options only after the ACL apply validates its plan Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: add only missing grant options before an ACL apply, never default privileges Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: run one data table ACL apply at a time per server before it connects Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: hold the ACL connection to the database that was authorized Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: build the ACL connection from the authorized data table entry Resolving the settings again could land on a resource with the same database name on another server, which the later entry checks never see. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * fix: check ACL read reach against the entry it connects from Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BRoYE5ZeAVvrDYdfhDAYXb * chore: update ee-repo-ref to 7e338e4dabf91689bfd7fb0333c6534040b17b59 This commit updates the EE repository reference after PR #787 was merged in windmill-ee-private. Previous ee-repo-ref: 0edd40979cf36bfba59323f3f6a0811ae1369cf5 New ee-repo-ref: 7e338e4dabf91689bfd7fb0333c6534040b17b59 Automated by sync-ee-ref workflow. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
45 lines
1.6 KiB
Rust
45 lines
1.6 KiB
Rust
/*
|
|
* Author: Ruben Fiszel
|
|
* Copyright: Windmill Labs, Inc 2022
|
|
* This file and its contents are licensed under the AGPLv3 License.
|
|
* Please see the included NOTICE for copyright information and
|
|
* LICENSE-AGPL for a copy of the license.
|
|
*/
|
|
|
|
//! Where the ACL planner comes from: the enterprise one, or a refusal.
|
|
//!
|
|
//! Data table roles are an Enterprise Edition feature, and so is everything here — reading who
|
|
//! owns what included. `private` alone is not that edition — community builds carry it — so the
|
|
//! planner is behind `enterprise` as well.
|
|
|
|
#[cfg(all(feature = "private", feature = "enterprise"))]
|
|
pub(crate) use crate::datatable_acl_ee::plan_statements;
|
|
|
|
#[cfg(all(feature = "private", feature = "enterprise"))]
|
|
pub(crate) fn ensure_datatable_acl_available() -> windmill_common::error::Result<()> {
|
|
Ok(())
|
|
}
|
|
|
|
#[cfg(not(all(feature = "private", feature = "enterprise")))]
|
|
use {
|
|
crate::datatable_acl::{AclChange, AclPlan, AclTarget, CatalogFacts},
|
|
windmill_common::{datatable_roles_oss::datatable_roles_unavailable, error::Result},
|
|
};
|
|
|
|
/// Checked first by every ACL route, before anything is read or connected to.
|
|
#[cfg(not(all(feature = "private", feature = "enterprise")))]
|
|
pub(crate) fn ensure_datatable_acl_available() -> Result<()> {
|
|
Err(datatable_roles_unavailable())
|
|
}
|
|
|
|
#[cfg(not(all(feature = "private", feature = "enterprise")))]
|
|
pub(crate) fn plan_statements(
|
|
_target: &AclTarget,
|
|
_change: &AclChange,
|
|
_dbname: &str,
|
|
_pg_role: &str,
|
|
_facts: &CatalogFacts,
|
|
) -> Result<AclPlan> {
|
|
Err(datatable_roles_unavailable())
|
|
}
|