mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-11 00:06:06 +00:00
* fix(frontend): mint password secrets in the operating workspace A `password: true` string argument is rendered by PasswordArgInput, which mints an ephemeral secret variable on the first keystroke and rebinds the argument to `$var:<path>`. It minted into `$workspaceStore` — the globally active navigation workspace. Session editors operate on a different, possibly forked workspace without switching `$workspaceStore`, and thread that operating workspace explicitly as a `workspace` prop. When the two diverged the secret landed where the user was merely looking while the job ran elsewhere, and the backend failed with `Variable not found`. Add the `workspace` prop to PasswordArgInput and thread it through every hop between a form mount and the minting field, plus the entry points that supply it. Track `mintedIn` so updates target where the variable actually lives, and re-mint when the operating workspace moves after a path already exists. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(frontend): keep a password field consistent with its argument A parent can replace the whole args object without remounting this field — previewing a saved input, say — leaving `path` and `password` describing a secret the argument no longer points at. Minting from them then copies the old plaintext over the replacement, and the replacement is lost. State that rule once as `argReplaced` and gate every mint on it. The replacement can also land while the create is in flight, so the bound value is captured before the request and re-checked after it resolves; the variable that mint produced was never referenced, so it is deleted outright. A mint that ends without binding re-seeds `password` from what the argument now holds, so the field stops displaying a secret that will not be submitted and a later workspace move cannot re-mint the stale plaintext. `updateValue` returns early before anything is minted, since its 404 retry would otherwise bind over a replacement it cannot see. A failed initial mint now raises a toast rather than passing silently, which also removes the component's last unhandled rejection. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(frontend): guard workspace forwarding to PasswordArgInput Every hop between the form a caller mounts and the PasswordArgInput that mints the secret must forward `workspace`, and so must the entry points that supply it. A hop that drops the prop falls back to the navigation workspace while the top-level case keeps passing, and no typechecker catches it because every hop declares `workspace?: string | undefined`. The forwarded expression is checked rather than the prop's presence, so `workspace={$workspaceStore}` and `workspace={undefined}` fail. Two ways the scan could stop guarding without failing are asserted too: an unterminated mount raises instead of swallowing the rest of the file, and the number of mounts parsed must equal the number of tag occurrences, so a mount written inline rather than at the start of a line fails loudly. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(frontend): list and create variables in the operating workspace * fix(frontend): surface and bound a failed recovery mint * test(frontend): end a mount at the first line closing it --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>