Files
windmill/backend
Ruben FiszelandClaude Opus 4.8 cb8fa45114 fix: reuse VALID_EMAIL, guard app_path, accept base64url JWT headers
- Validate the email claim with `windmill_common::users::VALID_EMAIL` (the `usr`
  table's own constraint) plus the 254-byte bound, rather than a hand-rolled
  predicate. It requires an `@`, which is what keeps a guest's name its own
  principal, never a `u/<user>` or `g/<group>`.
- Reject an `app_path` claim carrying a scope metacharacter (`*`, `,`, `:`,
  whitespace) before authenticating: it is interpolated into `apps:read:<path>`
  and `apps:run:<path>`, where `*` or `,` would widen the guest past its one app.
- `isJwt` on the custom-path route normalises base64url before `atob`, so a
  header carrying `-`/`_` (a `kid`, a signature) is recognised instead of taken
  for a path segment; it also checks the three-segment structure.
- Drop the dead stale-key carry-forward in the blocking JWKS path (a stale-good
  entry is served by the fast path) and clean up the test's env var.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VF3v6LA9399gNphmZaHYG3
2026-09-03 16:54:36 +00:00
..

Windmill Backend

This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.

Components

name description
windmill-api The API server, exposing functionality to other components and the frontend
windmill-audit Contains audit functionality, allowing different components to record important actions
windmill-common Common code shared by all crates
windmill-queue Contains job & flow queuing functionality, commonly written to by the API server and read from by workers
windmill-worker The worker. Used to process and execute flows & jobs.
parsers Contains code to parse signatures in different langauges.

Compile sqlx for offline ci

cargo sqlx prepare --workspace -- --bin windmill --features enterprise