mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 08:02:19 +00:00
* feat: let a workspace withdraw operator schedule and trigger writes Operators can create, edit and delete schedules and triggers today through the API, CLI and MCP, while the operator_settings flags beside them only hide those pages. An admin who wants operators to see what is scheduled without letting them change it cannot express that. Add manage_schedules and manage_triggers as enforced settings, gated at the schedule handlers and at the generic TriggerCrud routes so every trigger kind is covered by one check. They name capabilities operators already hold, so they are granted unless withdrawn, and absence has to mean "never configured" rather than a value. The read coalesces to true; the update endpoint merges into the stored jsonb with the two fields as Option<bool>, so an omitted key keeps what is stored. operator_settings is git-synced as a whole object, so a settings file written before these keys existed reaches the endpoint on every pull, and a serde or SQL default of either polarity would turn that pull into a silent withdrawal or restoration. The rights are read through a per-process cache, so withdrawing one publishes a notify_event that drops the entry on every replica. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4 * feat: let operators compose flows when the workspace grants the right Adds operator_settings.builder_flows: a workspace setting that lets every operator compose flows out of runnables that already exist. It does not make them authors. The boundary the operator role draws is authoring code and running arbitrary code, and this does not move it: check_flow_is_composition_only walks the value and refuses anything carrying code, including the shapes an obvious walk misses (code hoisted into a flow_node, an AI agent step's tools, and a linked ai_agent resource whose tool list is resolved at run time). What the walk cannot settle it returns for the caller to authorize under RLS: the worker tags the steps pin, every runnable they reference, and the (path, hash) of every version-pinned step. Composing a path is enough to run it and to run it as whoever it runs as, since the worker resolves a step's path with the root DB handle and adopts that runnable's on_behalf_of. A pinned hash needs its own check because dispatch ignores the path beside it. The gate runs on every write and on both request-supplied-value paths, flow preview and flow dependencies, or either becomes the way to run what the write path refuses. Operators of a builder workspace consume a full author seat; the EE companion carries the counting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4 * feat: enforce operator write rights on the router and in the UI Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: close the capture gap and gate the trigger editors' write actions Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: gate acl writes and the native trigger drawer behind manage rights Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: refuse operator writes with 403 and gate sharing at the drawer Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * perf: resolve identity in the operator write gate only for writes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: gate the suspended-jobs actions and stop the route check refusing reads Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: explain the empty-state create button when operator writes are withdrawn Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: audit operator settings changes and fold path writes into native rows Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: open locked editors read-only and group the operator settings Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: skip email and azure lookups on editor open while triggers are locked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs: state each operator-rights rationale once in comments Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: address CI review findings on operator write rights Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep capture move gated and skip it in the builders while locked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: refuse builder-rights violations with 403 so operators stay logged in Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * refactor: trim duplication in the operator builder gates Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: hide build app from builder operators on the flow page Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: point at the companion EE PR merged with EE main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep a builder's drafts list loading past drafts they cannot write Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: hide saved agents from builder operators in the step picker Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: note the inlined seat rule and drop orphaned sqlx entries Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: stop a builder's step test from logging them out Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: refuse a builder's dependency job on a path it cannot write Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep builders from adding dynamic dropdown code to a flow A flow's dropdown code runs as whoever loads its form, so a builder may keep or drop the code stored on the flow it updates, never add or change it. The builder's editor hides the dropdown types and code, and previews options through the deployed flow; the inline dropdown refusal is a 403 so it no longer logs operators out. Also trims rationale comments repeated across sites. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: show why saving operator settings failed The seat-cap refusal on granting builder rights explains what to do; the toast now carries the server's message instead of a generic failure. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: check builder flow drafts like deploys and treat dropdown code as code A developer who loads a builder's flow draft in the editor runs its dynamic dropdown code as themselves, so a builder's draft now passes the same checks as a deploy. Dropdown code is refused like step code rather than kept or dropped, which also removes the exact-match comparison that refused builders over whitespace. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: bill a builder workspace's operators as developers on cloud The cloud seat count behind the Premium page, the sidebar usage and the fork cap still weighed every operator at half a seat, while the builder right makes them authors. The out-of-repo invoicing job must follow the same rule. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: check a builder's flow draft as it will be stored Draft storage strips NUL escapes after the builder check, so a key ending in one (value\u0000, x-windmill-dyn-select-code\u0000) passed the check as an unknown field and was stored under its plain name. The check now reads the sanitized text. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: list a builder's flow drafts and hide hub imports from builders A builder's undeployed flows now appear in the home list, the flow list and the folder counts. Hub project imports and templates bring scripts and apps along, so builders are no longer offered them. The docs record builders' JavaScript expressions as an accepted risk. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: keep the stored builder right when a settings payload omits it A git-synced settings file written before the key existed withdrew the right on every push. builder_flows now follows the manage_* rights: an omitted key leaves the stored value, and the CLI does not count it as a difference. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: word builder refusals by what the flow contains, test the tag refusal A builder refused on a developer's flow never changed its code, so the refusals now describe the flow ("has inline code, so only a developer can edit this flow") rather than an authoring attempt. The grant confirmation uses the neutral dialog: granting changes billing but destroys nothing. The integration test pins the refusal of a worker tag the workspace cannot use. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: read builder rights from the operating workspace, gate the flow page's audit logs entry Builder rights now come from useOperatorBuilderFlows(), next to the schedule and trigger locks, so an editor embedded for another workspace answers about that workspace; the legacy AI chat, one instance for the whole app, reads the navigation workspace. The flow page's Audit logs entry follows the operator audit_logs setting now that builders open that menu. Operator settings reset every value on load, null settings included, so nothing carries over from the previous workspace. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: pick a dynamic dropdown's code source by the operating user's role The flow input editor, the flow test panel and the flow chat send the dropdown request to the operating workspace, so they now also choose inline versus deployed code by the role held there, through useOperatingUser(), instead of the navigation workspace's. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: update ee-repo-ref to 40ac1c5f8cbce3843b582d9b392d3f3cc7eca3e6 This commit updates the EE repository reference after PR #815 was merged in windmill-ee-private. Previous ee-repo-ref: 31c9e66884b8ca805b20bbfad41fc428fbedbc0e New ee-repo-ref: 40ac1c5f8cbce3843b582d9b392d3f3cc7eca3e6 Automated by sync-ee-ref workflow. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
260 lines
11 KiB
Rust
260 lines
11 KiB
Rust
//! Regression test for the inline preview authorization bypass (GHSA-pp5h-96x3-3wqq).
|
|
//!
|
|
//! `POST /api/w/:workspace/jobs/run_inline/preview` -> `run_inline_preview_script`
|
|
//! runs request-supplied code inline (in-process via DuckDB), i.e. it is an
|
|
//! arbitrary-code-execution sibling of `/jobs/run/preview`. The bug was that
|
|
//! this handler was missing the Operator guard that `run_preview_script`
|
|
//! enforces, so an authenticated Operator (a run-only user who must not be able
|
|
//! to run preview jobs) could execute arbitrary code in a single request. This
|
|
//! was the incomplete-fix residual of CVE-2026-22683, whose v1.615.0 patch only
|
|
//! covered the entity-CRUD endpoints and left this direct inline-exec sink open.
|
|
//!
|
|
//! The guard on both routes has one exemption: `wmill.datatable()` called from
|
|
//! inside a job the operator is running. Operators can only run deployed code,
|
|
//! so a request the job's WM_TOKEN authenticates comes from code a non-operator
|
|
//! authored, and the exemption is limited to the request shape the helper sends
|
|
//! (PostgreSQL against a `datatable://` database) so a leaked WM_TOKEN cannot
|
|
//! be replayed to run anything else.
|
|
//!
|
|
//! This test pins down:
|
|
//! - an Operator's own token is rejected by the operator guard (the core fix;
|
|
//! pre-fix this reached the inline executor instead of returning 403),
|
|
//! - a regular non-operator passes the guard (the fix must not over-block the
|
|
//! legitimate inline preview flow): in the test harness the worker inline
|
|
//! utils are not registered, so a caller past the guard gets the distinct
|
|
//! "worker inline functions" error rather than the operator rejection,
|
|
//! - an Operator's job token passes the guard for a datatable query while its
|
|
//! job is running, on the inline route and on the `/jobs/run/preview`
|
|
//! fallback the SDKs use when the worker has no internal server,
|
|
//! - the same token is rejected for any other payload (in-process DuckDB, or a
|
|
//! `-- database` directive redirecting the query, whether written literally or
|
|
//! reached through a `WM_INTERNAL_DB` marker) and for a deferred run,
|
|
//! - an Operator's job token for a job that is not running, whether finished or
|
|
//! merely queued, is rejected.
|
|
|
|
use serde_json::json;
|
|
use sqlx::{Pool, Postgres};
|
|
use windmill_common::auth::create_jwt_token;
|
|
use windmill_common::db::Authed;
|
|
use windmill_test_utils::*;
|
|
|
|
fn client() -> reqwest::Client {
|
|
reqwest::Client::new()
|
|
}
|
|
|
|
fn authed(builder: reqwest::RequestBuilder, token: &str) -> reqwest::RequestBuilder {
|
|
builder.header("Authorization", format!("Bearer {}", token))
|
|
}
|
|
|
|
/// An inline preview request: request-supplied `content` to run via DuckDB.
|
|
fn inline_preview_body() -> serde_json::Value {
|
|
json!({
|
|
"language": "duckdb",
|
|
"content": "SELECT content FROM read_text(['/etc/passwd']);",
|
|
"args": {}
|
|
})
|
|
}
|
|
|
|
/// The request `wmill.datatable("main")` sends: PostgreSQL against `datatable://main`.
|
|
fn datatable_query_body() -> serde_json::Value {
|
|
json!({
|
|
"language": "postgresql",
|
|
"content": "SELECT 1 AS x;",
|
|
"args": { "database": "datatable://main" }
|
|
})
|
|
}
|
|
|
|
/// Mint the WM_TOKEN a job hands its own code: an internally-signed job JWT
|
|
/// (note the `job_id` claim) for the fixture's operator, exactly as the worker
|
|
/// issues it when the operator runs a deployed script.
|
|
async fn operator_job_token(job_id: uuid::Uuid) -> String {
|
|
let authed = Authed {
|
|
email: "operator@windmill.dev".to_string(),
|
|
username: "operator-user".to_string(),
|
|
is_admin: false,
|
|
is_operator: true,
|
|
groups: vec![],
|
|
folders: vec![],
|
|
scopes: None,
|
|
token_prefix: None,
|
|
};
|
|
create_jwt_token(
|
|
authed,
|
|
"test-workspace",
|
|
3600,
|
|
Some(job_id),
|
|
Some("ephemeral-script".to_string()),
|
|
None,
|
|
None,
|
|
)
|
|
.await
|
|
.expect("mint operator job token")
|
|
}
|
|
|
|
const OPERATOR_GUARD_MSG: &str = "Operators cannot run preview jobs";
|
|
|
|
/// The fixture's deployed-script jobs of the operator: one running, one queued.
|
|
const RUNNING_JOB_ID: &str = "2aa0c0de-0000-4000-8000-000000000001";
|
|
const QUEUED_JOB_ID: &str = "2aa0c0de-0000-4000-8000-000000000002";
|
|
|
|
async fn post(url: &str, token: &str, body: &serde_json::Value) -> (u16, String) {
|
|
let resp = authed(client().post(url), token)
|
|
.json(body)
|
|
.send()
|
|
.await
|
|
.expect("request");
|
|
let status = resp.status().as_u16();
|
|
let body = resp.text().await.expect("body");
|
|
(status, body)
|
|
}
|
|
|
|
#[sqlx::test(fixtures("base", "inline_preview_auth"))]
|
|
async fn test_inline_preview_authorization(db: Pool<Postgres>) -> anyhow::Result<()> {
|
|
initialize_tracing().await;
|
|
// The server decodes WM_TOKENs with the same in-process JWT secret, so
|
|
// setting it once lets us mint valid ones below.
|
|
set_jwt_secret().await;
|
|
|
|
let server = ApiServer::start(db.clone()).await?;
|
|
let port = server.addr.port();
|
|
let url = format!("http://localhost:{port}/api/w/test-workspace/jobs/run_inline/preview");
|
|
|
|
// 1. CORE REGRESSION: an Operator must be rejected by the operator guard.
|
|
// Pre-fix this fell through to the inline executor (arbitrary code
|
|
// execution); post-fix it returns 403 with the operator guard message.
|
|
let (status, body) = post(&url, "OPERATOR_TOKEN", &inline_preview_body()).await;
|
|
assert_eq!(
|
|
status, 403,
|
|
"Operator must be rejected from inline preview (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
body.contains(OPERATOR_GUARD_MSG),
|
|
"rejection must be the operator guard, got: {body}"
|
|
);
|
|
|
|
// 2. The fix must NOT over-block a legitimate non-operator: a regular member
|
|
// passes the operator + scope checks. The test harness does not register
|
|
// the worker inline utils, so the request proceeds past the guard and
|
|
// fails later with the distinct "worker inline functions" error — proving
|
|
// the operator guard did not reject it.
|
|
let (status, body) = post(&url, "SECRET_TOKEN_2", &inline_preview_body()).await;
|
|
assert_ne!(
|
|
status, 403,
|
|
"non-operator must not be blocked by the operator guard (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
!body.contains(OPERATOR_GUARD_MSG),
|
|
"non-operator must not hit the operator guard, got: {body}"
|
|
);
|
|
|
|
// 3. The WM_TOKEN of a deployed-script job the Operator is running passes the
|
|
// guard for a datatable query: this is `wmill.datatable()` called from
|
|
// inside that job. As in 2, the harness then fails with the "worker inline
|
|
// functions" error.
|
|
let running_job_token =
|
|
operator_job_token(uuid::Uuid::parse_str(RUNNING_JOB_ID).unwrap()).await;
|
|
let (status, body) = post(&url, &running_job_token, &datatable_query_body()).await;
|
|
assert_ne!(
|
|
status, 403,
|
|
"operator job token of a running job must pass the guard for a datatable query (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
!body.contains(OPERATOR_GUARD_MSG),
|
|
"operator job token of a running job must not hit the operator guard, got: {body}"
|
|
);
|
|
|
|
// 4. The same token is rejected for any other payload: the exemption covers
|
|
// the datatable request shape only, never in-process DuckDB, and never a
|
|
// `-- database` directive, which the executor honors over `args.database`.
|
|
let mut redirected = datatable_query_body();
|
|
redirected["content"] = json!("-- database u/test-user/other_db\nSELECT 1 AS x;");
|
|
let mut to_s3 = datatable_query_body();
|
|
to_s3["content"] = json!("-- s3\nSELECT 1 AS x;");
|
|
let mut resource_db = datatable_query_body();
|
|
resource_db["args"]["database"] = json!("$res:u/test-user/other_db");
|
|
// A marker is a single line the directive regexes cannot match; the directive only
|
|
// appears once the executor expands it, so the guard must check the expansion.
|
|
let mut marker = datatable_query_body();
|
|
marker["content"] = json!(concat!(
|
|
r#"-- WM_INTERNAL_DB_SELECT {"table":"t","columnDefs":[{"field":"id","datatype":"int4"}],"#,
|
|
r#""whereClause":"true\n-- database u/test-user/other_db\n AND true"}"#
|
|
));
|
|
for (label, payload) in [
|
|
("DuckDB", inline_preview_body()),
|
|
("database directive", redirected),
|
|
("s3 directive", to_s3),
|
|
("resource database", resource_db),
|
|
("marker-expanded database directive", marker),
|
|
] {
|
|
let (status, body) = post(&url, &running_job_token, &payload).await;
|
|
assert_eq!(
|
|
status, 403,
|
|
"operator job token must be rejected for a {label} payload (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
body.contains(OPERATOR_GUARD_MSG),
|
|
"rejection for a {label} payload must be the operator guard, got: {body}"
|
|
);
|
|
}
|
|
|
|
// 5. An Operator's job token whose job is not running is rejected like the
|
|
// operator's own token, whether the job is over (no queue row) or merely
|
|
// queued: a WM_TOKEN that leaked through logs cannot be replayed once the
|
|
// job is over.
|
|
for (label, job_id) in [
|
|
("finished", uuid::Uuid::new_v4()),
|
|
("queued", uuid::Uuid::parse_str(QUEUED_JOB_ID).unwrap()),
|
|
] {
|
|
let token = operator_job_token(job_id).await;
|
|
let (status, body) = post(&url, &token, &datatable_query_body()).await;
|
|
assert_eq!(
|
|
status, 403,
|
|
"operator job token of a {label} job must be rejected (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
body.contains(OPERATOR_GUARD_MSG),
|
|
"rejection for a {label} job must be the operator guard, got: {body}"
|
|
);
|
|
}
|
|
|
|
// 6. The SDKs fall back to `/jobs/run/preview` when the worker has no internal
|
|
// server (agent workers). The same exemption applies there: the running
|
|
// job's token queues the datatable query (201 with the job id), the
|
|
// operator's own token is still refused.
|
|
let fallback_url = format!("http://localhost:{port}/api/w/test-workspace/jobs/run/preview");
|
|
let (status, body) = post(&fallback_url, &running_job_token, &datatable_query_body()).await;
|
|
assert_eq!(
|
|
status, 201,
|
|
"operator job token of a running job must queue a datatable preview (got {status}): {body}"
|
|
);
|
|
let (status, body) = post(&fallback_url, "OPERATOR_TOKEN", &datatable_query_body()).await;
|
|
assert_eq!(
|
|
status, 403,
|
|
"Operator must be rejected from the preview fallback (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
body.contains(OPERATOR_GUARD_MSG),
|
|
"rejection must be the operator guard, got: {body}"
|
|
);
|
|
|
|
// 7. A deferred run on the fallback would outlive the running job the
|
|
// exemption keys off, so the running job's token cannot schedule one.
|
|
for deferral in [
|
|
"scheduled_in_secs=86400",
|
|
"scheduled_for=2099-01-01T00:00:00Z",
|
|
] {
|
|
let deferred_url = format!("{fallback_url}?{deferral}");
|
|
let (status, body) = post(&deferred_url, &running_job_token, &datatable_query_body()).await;
|
|
assert_eq!(
|
|
status, 403,
|
|
"operator job token must not schedule a deferred preview with {deferral} (got {status}): {body}"
|
|
);
|
|
assert!(
|
|
body.contains(OPERATOR_GUARD_MSG),
|
|
"rejection for {deferral} must be the operator guard, got: {body}"
|
|
);
|
|
}
|
|
|
|
Ok(())
|
|
}
|