mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-06 08:01:35 +00:00
Owning the target is not owning what a change through it covers: a scope that reads IN SCHEMA names every object in the schema, and handing a schema over takes them all with it. Postgres would have skipped the ones the caller does not own — these statements run as the data table's admin, so it will not. Refuse, naming the object that is not theirs, and let a workspace admin through as before. A default-privilege rule speaks for the role that creates the objects, so a non-admin now only writes them for the roles they may run as. Also: the revoke button follows can_manage like the grant builder already did, the copy path resolves a data table as admin for an admin (dumping as a restricted role silently omits what it cannot read), and two doc comments now sit on the function they describe.
Windmill frontend
The Windmill frontend written in Svelte 5 + Tailwind CSS
The frontend is under AGPL, see the LICENSE file at the root of this repo