mrhid6
e5363a64ee
fix(server): per-org settings and ESO read token
...
The settings collection was a single global document, so every org
shared one SMTP config, alert config, retention policy and ESO read
token. GetSecretGroupDecryptedAny then flattened every org's secrets
for a group into one map, meaning any tenant's token read every
tenant's secrets.
- settings gains org_id; GetSettings/SaveSettings/RotateSecretsReadToken/
GetWorkflowLogRetentionDays all take orgID
- VerifySecretsReadToken replaced by ResolveSecretsReadToken, which
resolves the org from the presented token's hash; the ESO endpoint
derives its org from the token rather than a session, since it is
called machine-to-machine
- GetSecretGroupDecryptedAny deleted in favour of the org-scoped variant
- settings and token-rotation routes now require owner/admin
- offline sweep and log retention resolve org per server / per run
- migration 0002 stamps the legacy settings doc with the default org
Note: /api/settings now 403s for members; the web settings page needs a
matching role check.
2026-07-22 09:35:47 +01:00
mrhid6
5a701acc82
fix: Removed tests
2026-07-22 09:31:29 +01:00
mrhid6
dff3668a25
fix(server): validate cross-org resource ownership
...
Review of the org-scoping pass found that org_id on a query filter
protects the row you look up, but does nothing when a handler accepts a
foreign resource ID as data and a downstream unscoped query consumes it.
- AssignKey: verify key and server both belong to the org
- BuildAuthorizedKeys: resolve server first, scope assignments and keys
to that server's org (was honouring foreign assignment rows)
- Workflows: validate TargetServerIDs on create/update and re-check at
trigger time
- Monitor incidents/uptime handlers: gate on org-scoped GetMonitor
- GetChannels: take orgID; validate channel_ids on monitor create/update
- Secret and default-step unique indexes: scope to org_id so a second
org no longer hits E11000
- DeleteServer/DeleteMonitor: scope cascading deletes
2026-07-22 09:28:43 +01:00
mrhid6
850aa0ed05
feat(server): org-scope service layer + handlers + org admin API
...
Threads org_id through every admin-facing service function (servers, keys,
assignments, secrets, workflows/steps/runs, monitors, channels, audit),
adds RequireRole middleware, and wires /api/org user + OIDC management
routes. Agent/scheduler paths keep unique-key signatures and resolve org
from the loaded record; internal-only helpers (getServerByID,
getRunByID, getMonitorByID) preserve those call sites.
2026-07-21 16:56:39 +01:00
mrhid6
d0ed9885e7
feat(auth): per-org OIDC resolver replaces global provider
2026-07-21 16:41:50 +01:00
mrhid6
ff22340561
feat(auth): host-based org resolution + session/host match guard
2026-07-21 16:38:24 +01:00
mrhid6
2038e86b53
feat(auth): local email/password login + first-run bootstrap
2026-07-21 16:36:13 +01:00
mrhid6
404214d82e
fix(services): keep original step Slugify; org reuses it
2026-07-21 16:33:31 +01:00
mrhid6
01fd2e201e
feat(services): org create+slug and user service with bcrypt
2026-07-21 16:30:42 +01:00
mrhid6
066095ffca
feat(auth): session carries org_id/role; add context helpers
2026-07-21 16:28:06 +01:00
mrhid6
022b1ef8ec
feat(server): auth indexes + default-org backfill migration
2026-07-21 16:25:37 +01:00
mrhid6
a8771a6e4d
style(models): gofmt org_id field alignment
2026-07-21 16:24:16 +01:00
mrhid6
502045d3af
feat(models): add org/user/org_oidc models and org_id on scoped collections
2026-07-21 16:23:14 +01:00
mrhid6
ea73fc3a18
docs(plan): saas auth + orgs implementation plan
2026-07-21 16:20:20 +01:00
mrhid6
75b86e3843
docs(spec): add org slug, host-based resolution, single gRPC endpoint
2026-07-21 16:15:29 +01:00
mrhid6
9767e18123
chore: removed old plans
2026-07-21 15:54:11 +01:00
mrhid6
19b4aef95b
feat(server): dark-themed HTML email notification template
Server Deploy / deploy (push) Successful in 1m22s
2026-07-21 15:14:57 +01:00
mrhid6
0464c540b2
feat: edit monitors + notification channels; HTTP monitor insecure-TLS option
Server Deploy / deploy (push) Successful in 2m9s
Agent Release / build (push) Successful in 10m39s
Agent Release / msi (push) Successful in 35s
2026-07-21 14:55:41 +01:00
mrhid6
45178d455e
fix(server): SMTP dispatch dial timeout + implicit/STARTTLS handling
Server Deploy / deploy (push) Successful in 2m19s
2026-07-21 14:46:15 +01:00
mrhid6
f28ab1a741
feat(web): redesign settings page, drop legacy webhook/email alerting UI
Server Deploy / deploy (push) Successful in 1m24s
2026-07-21 14:40:36 +01:00
mrhid6
df6f8b6f62
feat(web): notification channel settings UI
Server Deploy / deploy (push) Successful in 1m24s
2026-07-21 14:24:38 +01:00
mrhid6
8f3a27100f
feat(server): multi-channel monitor notifications
Server Deploy / deploy (push) Successful in 1m16s
2026-07-21 14:22:55 +01:00
mrhid6
69c7a352f6
feat(agent): agent-run monitor scheduler
Server Deploy / deploy (push) Successful in 1m21s
Agent Release / build (push) Successful in 10m43s
Agent Release / msi (push) Successful in 1m5s
2026-07-21 14:19:59 +01:00
mrhid6
a2bfa98a2d
feat(proto): SyncMonitors + ReportChecks RPCs
Server Deploy / deploy (push) Successful in 1m27s
2026-07-21 14:18:49 +01:00
mrhid6
57151826ae
feat(web): monitors list/detail/form UI
Server Deploy / deploy (push) Successful in 2m1s
2026-07-21 14:16:08 +01:00
mrhid6
e413009faa
feat(server): server-run monitor scheduler + REST API
Server Deploy / deploy (push) Successful in 58s
2026-07-21 14:13:26 +01:00
mrhid6
3ec9f1b35f
feat(server): monitor ingest pipeline, incidents, rollups
Server Deploy / deploy (push) Successful in 2m0s
2026-07-21 14:12:03 +01:00
mrhid6
e019493087
feat(server): monitor model + checker package
Server Deploy / deploy (push) Successful in 53s
2026-07-21 14:10:46 +01:00
mrhid6
ca2c05db14
feat(web): inventory panel on server detail
Server Deploy / deploy (push) Successful in 41s
2026-07-21 14:08:36 +01:00
mrhid6
1850f352a2
feat(agent): schedule inventory reporting (30s metrics, 15m static)
Server Deploy / deploy (push) Successful in 1m15s
2026-07-21 14:07:09 +01:00
mrhid6
850ffbafe1
feat(agent): /proc-based inventory collectors
Server Deploy / deploy (push) Successful in 16s
2026-07-21 14:06:11 +01:00
mrhid6
a28157dcf8
feat(server): store inventory and handle ReportInventory RPC
Server Deploy / deploy (push) Successful in 1m4s
2026-07-21 14:05:19 +01:00
mrhid6
03e2c3c50d
feat(proto): add ReportInventory RPC and inventory model
Server Deploy / deploy (push) Successful in 2m38s
2026-07-21 14:04:28 +01:00
mrhid6
fb1a1292ec
docs: add service monitoring phases to fleet inventory plan
Server Deploy / deploy (push) Successful in 21s
2026-07-21 14:01:50 +01:00
mrhid6
ec201a23a2
fix: Fixed draft workflow status
Server Deploy / deploy (push) Successful in 41s
2026-07-21 12:09:19 +01:00
mrhid6
d9a33b0672
fix(web): stop autosave loop by ignoring volatile server-echo fields
Server Deploy / deploy (push) Successful in 39s
2026-07-21 12:01:57 +01:00
mrhid6
2b7ef98dff
fix(web): move autosave hooks above early return (React #310 )
Server Deploy / deploy (push) Successful in 1m37s
2026-07-21 11:55:20 +01:00
mrhid6
b5f30bc7c8
Merge feat/step-picker-modal: autosave, step-picker modal, Steps page
Server Deploy / deploy (push) Successful in 1m22s
2026-07-21 11:51:03 +01:00
mrhid6
3a0116248e
fix(web): guard autosave against in-flight lost-update race
2026-07-21 11:50:53 +01:00
mrhid6
6af0a88841
feat(web): add Steps to main nav
2026-07-21 11:45:43 +01:00
mrhid6
e4c3fc24d3
feat(web): standalone Steps management page
2026-07-21 11:43:42 +01:00
mrhid6
e46d0edbf2
feat(web): replace builder step sidebar with Add-step modal
2026-07-21 11:41:37 +01:00
mrhid6
a4c4a72dbc
feat(web): StepPickerModal step picker component
2026-07-21 11:37:47 +01:00
mrhid6
67d729b360
feat(web): api.stepUsage binding
2026-07-21 11:36:03 +01:00
mrhid6
da6d825f45
fix(server): TestMain must not exit(0) before m.Run(); skip DB test individually
2026-07-21 11:34:56 +01:00
mrhid6
93423e32e6
feat(server): step usage counts endpoint
2026-07-21 11:31:05 +01:00
mrhid6
d0442291f5
feat(web): workflow builder autosave with last-saved status
2026-07-21 11:27:55 +01:00
mrhid6
6c5472760b
Merge branch 'feat/adhoc-steps-import-export': ad-hoc steps, step import/export, default steps, auto-derived outputs
Server Deploy / deploy (push) Successful in 1m26s
2026-07-21 10:42:02 +01:00
mrhid6
7c4a676742
fix: inline step secrets + inline input/output display + import body limit
2026-07-21 10:40:45 +01:00
mrhid6
fbda26a188
feat(web): ad-hoc inline steps + import-to-inline in workflow editor
2026-07-21 10:34:51 +01:00
mrhid6
90ce7af769
feat(web): step export/import, sync defaults, auto outputs, default badge
2026-07-21 10:31:28 +01:00
mrhid6
b543cd1b3d
feat(web): api client for step import/export/inline/defaults
2026-07-21 10:28:41 +01:00
mrhid6
15c9da1b01
feat(server): default steps seed-on-boot + admin re-sync
2026-07-21 10:25:41 +01:00
mrhid6
baa7bb239d
feat(server): step import/export/parse endpoints
2026-07-21 10:22:35 +01:00
mrhid6
7342c46d99
feat(server): auto-derive outputs on save + resolve inline steps
2026-07-21 10:20:12 +01:00
mrhid6
813f9e6fef
feat(server): derive declared_outputs from script + slugify
2026-07-21 10:17:50 +01:00
mrhid6
434f14ae3a
feat(server): inline step ref + workflow validation
2026-07-21 10:15:52 +01:00
mrhid6
8398fd2279
docs: implementation plan for adhoc steps, import/export, defaults, auto-outputs
2026-07-21 10:11:16 +01:00
mrhid6
56f06b9eaf
docs: auto-derive declared_outputs from script scan
2026-07-21 10:05:45 +01:00
mrhid6
d9d241f83b
docs: design for adhoc steps, step import/export, default steps
2026-07-21 09:59:34 +01:00
mrhid6
aee910c1f8
fix: fixed variable inputs
Server Deploy / deploy (push) Successful in 1m22s
2026-07-20 18:00:47 +01:00
mrhid6
bea545e873
feat: More verbose logging on workflow logs
Agent Release / build (push) Successful in 45s
Agent Release / msi (push) Successful in 42s
Server Deploy / deploy (push) Successful in 1m52s
2026-07-20 17:35:58 +01:00
mrhid6
82d7dde5f8
fix: Fixed style on workflow run
Server Deploy / deploy (push) Successful in 42s
2026-07-20 16:44:53 +01:00
mrhid6
397016ad68
feat: Updated workflow runs page
Server Deploy / deploy (push) Successful in 1m20s
2026-07-20 16:00:41 +01:00
mrhid6
39348c9491
feat(web): live SSE log tail and log retention setting
Server Deploy / deploy (push) Successful in 1m35s
2026-07-20 15:18:36 +01:00
mrhid6
63dadf6239
feat(api): server-run log fetch and SSE stream endpoints
2026-07-20 15:18:35 +01:00
mrhid6
d905c99d32
feat(server): stream step logs to files, drop log bodies from run docs
2026-07-20 15:18:35 +01:00
mrhid6
85e1baf59a
feat(server): workflow log-writer registry, retention setting, sweeper
2026-07-20 15:18:35 +01:00
mrhid6
351ad59dd8
fix(web): reseed edit-workflow modal state on open
Server Deploy / deploy (push) Successful in 1m23s
2026-07-20 14:56:14 +01:00
mrhid6
dcc901b0d2
feat(web): workflow runs list page and navigation links
Server Deploy / deploy (push) Successful in 1m29s
2026-07-20 14:52:13 +01:00
mrhid6
99bf093f00
feat(web): rebuild workflow builder — mockup styling, drag-and-drop, inputs inspector
2026-07-20 14:48:29 +01:00
mrhid6
619ccd28cb
feat(web): edit-workflow modal (name/targets/delete)
2026-07-20 14:44:59 +01:00
mrhid6
f22f0a4729
feat(web): edit-base-step modal with inputs/outputs editor
2026-07-20 14:42:13 +01:00
mrhid6
78194daf5f
feat(web): builder tokens, Modal primitive, input-param types
2026-07-20 14:40:07 +01:00
mrhid6
f141767fc2
feat(workflows): inject step inputs into env; update returns workflow
2026-07-20 14:37:36 +01:00
mrhid6
05cd8e154b
feat(workflows): step input params model + cascade step delete
2026-07-20 14:34:50 +01:00
mrhid6
004cc03ba6
docs: add workflow builder v2 plan
2026-07-20 14:33:46 +01:00
mrhid6
236e89989f
docs: add workflow builder v2 spec
2026-07-20 14:30:55 +01:00
mrhid6
b0a2de8ca1
fix: Fixed workflow style topbar
Server Deploy / deploy (push) Successful in 1m20s
2026-07-20 13:55:17 +01:00
mrhid6
e9ac7be8c3
feat: updates to workflow page
Server Deploy / deploy (push) Successful in 36s
2026-07-20 13:35:35 +01:00
mrhid6
47690c58d9
fix: Fixed workflow id
Server Deploy / deploy (push) Successful in 1m14s
2026-07-20 12:49:43 +01:00
mrhid6
5d72088837
feat(agent): stream step output chunks over CommandStream
Agent Release / build (push) Successful in 44s
Server Deploy / deploy (push) Successful in 1m51s
Agent Release / msi (push) Successful in 1m23s
2026-07-20 12:36:37 +01:00
mrhid6
7a60295bc1
feat(proto): add StepOutputChunk streaming message
2026-07-20 12:34:32 +01:00
mrhid6
b48467fb6e
docs: add workflow log streaming plan
2026-07-20 12:32:57 +01:00
mrhid6
b5e828c9e8
docs: add workflow log streaming spec
2026-07-20 12:30:11 +01:00
mrhid6
98284f4387
fix(workflows): mask output env in persisted logs, preserve cancelled status, run agent step async
2026-07-20 12:01:35 +01:00
mrhid6
e35e8fc839
feat(web): workflow run detail page with live logs
2026-07-20 11:53:30 +01:00
mrhid6
2cd9bc1c89
feat(web): three-pane workflow builder
2026-07-20 11:50:00 +01:00
mrhid6
39980581b1
feat(web): workflows list page and sidebar link
2026-07-20 11:46:44 +01:00
mrhid6
6f478eb817
feat(web): workflow API client types and methods
2026-07-20 11:44:10 +01:00
mrhid6
ff3a94b888
fix(api): audit workflow run cancellation
2026-07-20 11:42:31 +01:00
mrhid6
631894084a
feat(api): workflow, step, and run REST endpoints
2026-07-20 11:40:36 +01:00
mrhid6
296e0179cb
feat(server): workflow runner with parallel fan-out and env threading
2026-07-20 11:37:04 +01:00
mrhid6
600126a913
feat(server): step library and workflow CRUD services
2026-07-20 11:33:33 +01:00
mrhid6
4872a26786
feat(models): add workflow, step, and run models
2026-07-20 11:31:37 +01:00
mrhid6
f0c86a3bdf
feat(agent): execute RunStepCmd with WORKFLOW_ENV capture
2026-07-20 11:29:14 +01:00
mrhid6
1b286762f6
feat(server): add pending step-result registry and stream delivery
2026-07-20 11:26:35 +01:00
mrhid6
3c77c20de8
feat(proto): add RunStepCmd and StepResult messages
2026-07-20 11:24:08 +01:00
mrhid6
9e53f21746
docs: add Fleet Inventory and SaaS auth/orgs specs + plans
2026-07-20 11:16:19 +01:00
mrhid6
ad35b32f5b
docs: add Server Workflows implementation plan
2026-07-20 11:05:43 +01:00