mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-08 08:04:25 +00:00
Owning the target is not owning what a change through it covers: a scope that reads IN SCHEMA names every object in the schema, and handing a schema over takes them all with it. Postgres would have skipped the ones the caller does not own — these statements run as the data table's admin, so it will not. Refuse, naming the object that is not theirs, and let a workspace admin through as before. A default-privilege rule speaks for the role that creates the objects, so a non-admin now only writes them for the roles they may run as. Also: the revoke button follows can_manage like the grant builder already did, the copy path resolves a data table as admin for an admin (dumping as a restricted role silently omits what it cannot read), and two doc comments now sit on the function they describe.
Windmill Backend
This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.
Components
| name | description |
|---|---|
| windmill-api | The API server, exposing functionality to other components and the frontend |
| windmill-audit | Contains audit functionality, allowing different components to record important actions |
| windmill-common | Common code shared by all crates |
| windmill-queue | Contains job & flow queuing functionality, commonly written to by the API server and read from by workers |
| windmill-worker | The worker. Used to process and execute flows & jobs. |
| parsers | Contains code to parse signatures in different langauges. |
Compile sqlx for offline ci
cargo sqlx prepare --workspace -- --bin windmill --features enterprise