Files
windmill/backend
Ruben FiszelandClaude Opus 4.8 bced402f33 harden: reject dash-led git hosts and scrub env on ansible ls-remote
Two follow-ups on the URL validation:

- `validate_git_repo_url` accepted `ssh://-oProxyCommand=<cmd>/path` (a dash-led
  host inside an allowed scheme) and relied on git to reject it. git's ssh
  transport passes the host to `ssh` as an argument, so on an older git this is
  command execution. Reject an authority whose host starts with `-`, for both
  the scheme'd and scp-like forms, so validation no longer depends on the
  worker's git version.

- `get_git_repo_full_head_commit_hash` ran `git ls-remote` with the worker's
  full inherited environment (no `env_clear`), so its transport-helper/ssh
  children could read worker secrets such as `DATABASE_URL`. Scrub the env down
  to PROXY/PATH/TZ/GIT_SSH_COMMAND, matching `clone_repo`.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-19 12:19:28 +00:00
..

Windmill Backend

This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.

Components

name description
windmill-api The API server, exposing functionality to other components and the frontend
windmill-audit Contains audit functionality, allowing different components to record important actions
windmill-common Common code shared by all crates
windmill-queue Contains job & flow queuing functionality, commonly written to by the API server and read from by workers
windmill-worker The worker. Used to process and execute flows & jobs.
parsers Contains code to parse signatures in different langauges.

Compile sqlx for offline ci

cargo sqlx prepare --workspace -- --bin windmill --features enterprise