mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-07 16:03:21 +00:00
Three instance-global routes gate on the caller's own `is_admin` claim, which `ApiAuthed.is_admin` carries into a WM_TOKEN (it is a workspace-admin claim, true for superadmins too). A job token is capped at workspace admin (GHSA-hfh4-cx4h-3fcr), so its is_admin claim must not authorize instance actions on a route with no workspace binding: - `unarchive_workspace` — unarchive an arbitrary workspace by id - `prune_concurrency_group` — delete a global concurrency group - `list_worker_groups` — return unobfuscated `env_vars_static` (may hold secrets) Add job-token-aware `is_instance_admin` / `require_instance_admin` helpers (the same shape as `require_super_admin` / `require_devops_role`) and use them at these three sites. Workspace-scoped `require_admin(authed.is_admin, ...)` gates are intentionally left unchanged — a workspace-admin job token is within the cap there. Regression added covering all three; verified it lets a WM_TOKEN unarchive/leak without the fix and is blocked with it. Reported by Codex CI review (P1) on #10124. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>