mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-12 08:05:44 +00:00
* fix(frontend): scope raw-app/flow/script editors to the session workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): scope flow and script editor operations to the session workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): scope flow preview, inline-script creation and datatable schema to the session workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review — thread session workspace through flow resource pickers, script fetch, preview cancel/recording and path collision check Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Claude review — pass session workspace to preview FlowStatusViewer and align FlowChatManager guards Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Pi review — show acting workspace in script-not-found message and fetch picked script from it in EditorBar Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 2 — thread session workspace into flow step test, raw-app inline runnable, inline editor toolbars and MCP OAuth path Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 3 — thread session workspace into dynamic-input helpers and the flow-preview argument side panel (history/saved-inputs/captures) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 4 — thread session workspace into nested flow/script drawers, flow chat inputs and the flow input side tabs Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 5 — thread session workspace into script-module fork/reload and key the raw-app schema cache by workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 6 — key the DB manager schema cache by acting workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): address Codex review round 7 — thread session workspace into resource-valued arg pickers and the editor variable/resource helper drawers Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(frontend): scope the flow asset explorer's ResourceEditorDrawer to the acting workspace Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix: thread acting workspace through flow asset explore controls Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix: thread acting workspace through SQL REPL, secret args, helper forms, S3 inputs, saved inputs Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
53 lines
1.8 KiB
TypeScript
53 lines
1.8 KiB
TypeScript
import type { Schema } from '$lib/common'
|
|
import { VariableService } from '$lib/gen'
|
|
import { get } from 'svelte/store'
|
|
import { userStore, workspaceStore } from '$lib/stores'
|
|
import { generateRandomString } from '$lib/utils'
|
|
|
|
/**
|
|
* Process args before job submission: for non-string fields marked as password/sensitive,
|
|
* create ephemeral secret variables and replace values with $jsonvar:path references.
|
|
* String password fields are already handled by PasswordArgInput (uses $var:).
|
|
*/
|
|
export async function processSecretArgs(
|
|
args: Record<string, any>,
|
|
schema: Schema | undefined,
|
|
// Workspace the ephemeral secret variable is created in — must match the
|
|
// workspace the preview job runs in, else $jsonvar: resolves to a missing var.
|
|
forceWorkspace?: string
|
|
): Promise<Record<string, any>> {
|
|
if (!schema?.properties) return args
|
|
|
|
const workspace = forceWorkspace ?? get(workspaceStore)
|
|
const user = get(userStore)
|
|
if (!workspace || !user) return args
|
|
|
|
const username = (user.username ?? user.email)?.split('@')[0]
|
|
if (!username) return args
|
|
const userPrefix = `u/${username}/secret_arg/`
|
|
|
|
const result = { ...args }
|
|
|
|
for (const [key, prop] of Object.entries(schema.properties)) {
|
|
if (!prop.password) continue
|
|
if (prop.type !== 'object') continue // only object types; strings handled by PasswordArgInput
|
|
if (result[key] == null || result[key] === undefined) continue
|
|
if (typeof result[key] === 'string' && result[key].startsWith('$jsonvar:')) continue // already processed
|
|
|
|
const path = userPrefix + generateRandomString(12)
|
|
await VariableService.createVariable({
|
|
workspace,
|
|
requestBody: {
|
|
value: JSON.stringify(result[key]),
|
|
is_secret: true,
|
|
path,
|
|
description: 'Ephemeral secret variable',
|
|
expires_at: new Date(Date.now() + 1000 * 60 * 60 * 24 * 7).toISOString()
|
|
}
|
|
})
|
|
result[key] = '$jsonvar:' + path
|
|
}
|
|
|
|
return result
|
|
}
|