mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-11 00:06:06 +00:00
The editor preview is same-origin and unsandboxed, so app code there already holds the editing user's session cookie. Minting a scoped bearer for it added an endpoint and a portable 12h credential without containing anything. Inject only BASE_URL and WM_WORKSPACE: `windmill-client` falls back to credentialed same-origin requests when it finds no token, so the SDK runs as the editing user. Drops POST /apps/preview_sdk_token and the mint/race handling in the editor. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA