Files
windmill/backend
Ruben FiszelandClaude Opus 4.8 efc62d8e78 fix: bound the guest PEM key length before decoding or storing
decoding_key_from_pem decoded an unbounded PEM: a well-formed key with an
oversized modulus passes the structural check, is stored in the unbounded TEXT
column, and is reparsed on every guest-JWT request. Refuse one longer than
MAX_GUEST_PEM_LEN (8 KiB) at the same choke point the save path validates
through, the way the JWKS URL is bounded. Also tighten two cap tests to assert
their specific error rather than a substring another cap shares.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VF3v6LA9399gNphmZaHYG3
2026-09-04 16:06:57 +02:00
..

Windmill Backend

This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.

Components

name description
windmill-api The API server, exposing functionality to other components and the frontend
windmill-audit Contains audit functionality, allowing different components to record important actions
windmill-common Common code shared by all crates
windmill-queue Contains job & flow queuing functionality, commonly written to by the API server and read from by workers
windmill-worker The worker. Used to process and execute flows & jobs.
parsers Contains code to parse signatures in different langauges.

Compile sqlx for offline ci

cargo sqlx prepare --workspace -- --bin windmill --features enterprise