Repository navigation
feat: add Workflows UI surface #217
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 11 commits
cce14c6
0d00af9
9d954a0
f7be128
ba100e7
1edfc17
33f10b3
4ec1612
4f1549a
aad25e0
cb0e236
de0b38a
6f96c93
d6d8616
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -22,8 +22,8 @@ use serde::Deserialize; | |
| use crate::state::AppState; | ||
|
|
||
| use super::workflow_helpers::{ | ||
| definition_hash, ensure_webhook_secret, run_record_to_json, spawn_workflow_execution, | ||
| validate_webhook_urls, workflow_record_to_json, | ||
| approval_record_to_json, definition_hash, ensure_webhook_secret, run_record_to_json, | ||
| spawn_workflow_execution, validate_webhook_urls, workflow_record_to_json, | ||
| }; | ||
| use super::{ | ||
| api_error, check_channel_access, check_token_channel_access, extract_auth_context, forbidden, | ||
|
|
@@ -358,6 +358,45 @@ pub async fn list_workflow_runs( | |
| Ok(Json(serde_json::json!(result))) | ||
| } | ||
|
|
||
| // ── GET /api/workflows/:id/runs/:run_id/approvals ──────────────────────────── | ||
|
|
||
| /// List all approval records for a workflow run. | ||
| pub async fn list_run_approvals( | ||
| State(state): State<Arc<AppState>>, | ||
| headers: HeaderMap, | ||
| Path((id_str, run_id_str)): Path<(String, String)>, | ||
| ) -> Result<Json<serde_json::Value>, (StatusCode, Json<serde_json::Value>)> { | ||
| let ctx = extract_auth_context(&headers, &state).await?; | ||
| sprout_auth::require_scope(&ctx.scopes, sprout_auth::Scope::ChannelsRead) | ||
| .map_err(scope_error)?; | ||
| let pubkey_bytes = ctx.pubkey_bytes.clone(); | ||
|
|
||
| let id = uuid::Uuid::parse_str(&id_str) | ||
| .map_err(|_| api_error(StatusCode::BAD_REQUEST, "invalid workflow UUID"))?; | ||
| let run_id = uuid::Uuid::parse_str(&run_id_str) | ||
| .map_err(|_| api_error(StatusCode::BAD_REQUEST, "invalid run UUID"))?; | ||
|
|
||
| let workflow = state | ||
| .db | ||
| .get_workflow(id) | ||
| .await | ||
| .map_err(|_| not_found("workflow not found"))?; | ||
|
|
||
| if let Some(channel_id) = workflow.channel_id { | ||
| check_token_channel_access(&ctx, &channel_id)?; | ||
| check_channel_access(&state, channel_id, &pubkey_bytes).await?; | ||
| } | ||
|
Comment on lines
+385
to
+390
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This endpoint checks membership only when Useful? React with 👍 / 👎. |
||
|
|
||
| let approvals = state | ||
| .db | ||
| .get_run_approvals(id, run_id) | ||
| .await | ||
| .map_err(|e| internal_error(&format!("db error: {e}")))?; | ||
|
|
||
| let result: Vec<serde_json::Value> = approvals.iter().map(approval_record_to_json).collect(); | ||
| Ok(Json(serde_json::json!(result))) | ||
| } | ||
|
|
||
| // ── POST /api/workflows/:id/trigger ────────────────────────────────────────── | ||
|
|
||
| /// Manually trigger a workflow. Returns 202 Accepted; execution is async. | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,143 @@ | ||
| use reqwest::Method; | ||
| use serde::Serialize; | ||
| use tauri::State; | ||
|
|
||
| use crate::{ | ||
| app_state::AppState, | ||
| relay::{build_authed_request, send_empty_request, send_json_request}, | ||
| }; | ||
|
|
||
| // ── Reads ─────────────────────────────────────────────────────────────────── | ||
|
|
||
| #[tauri::command] | ||
| pub async fn get_channel_workflows( | ||
| channel_id: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/channels/{channel_id}/workflows"); | ||
| let request = build_authed_request(&state.http_client, Method::GET, &path, &state)?; | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn get_workflow( | ||
| workflow_id: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/workflows/{workflow_id}"); | ||
| let request = build_authed_request(&state.http_client, Method::GET, &path, &state)?; | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn get_workflow_runs( | ||
| workflow_id: String, | ||
| limit: Option<u32>, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let mut path = format!("/api/workflows/{workflow_id}/runs"); | ||
| if let Some(limit) = limit { | ||
| path.push_str(&format!("?limit={limit}")); | ||
| } | ||
| let request = build_authed_request(&state.http_client, Method::GET, &path, &state)?; | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| // ── Writes ────────────────────────────────────────────────────────────────── | ||
|
|
||
| #[derive(Serialize)] | ||
| struct CreateWorkflowBody { | ||
| yaml_definition: String, | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn create_workflow( | ||
| channel_id: String, | ||
| yaml_definition: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/channels/{channel_id}/workflows"); | ||
| let request = build_authed_request(&state.http_client, Method::POST, &path, &state)? | ||
| .json(&CreateWorkflowBody { yaml_definition }); | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[derive(Serialize)] | ||
| struct UpdateWorkflowBody { | ||
| yaml_definition: String, | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn update_workflow( | ||
| workflow_id: String, | ||
| yaml_definition: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/workflows/{workflow_id}"); | ||
| let request = build_authed_request(&state.http_client, Method::PUT, &path, &state)? | ||
| .json(&UpdateWorkflowBody { yaml_definition }); | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn delete_workflow( | ||
| workflow_id: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<(), String> { | ||
| let path = format!("/api/workflows/{workflow_id}"); | ||
| let request = build_authed_request(&state.http_client, Method::DELETE, &path, &state)?; | ||
| send_empty_request(request).await | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn trigger_workflow( | ||
| workflow_id: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/workflows/{workflow_id}/trigger"); | ||
| let request = build_authed_request(&state.http_client, Method::POST, &path, &state)?; | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| // ── Approvals ─────────────────────────────────────────────────────────────── | ||
|
|
||
| #[tauri::command] | ||
| pub async fn get_run_approvals( | ||
| workflow_id: String, | ||
| run_id: String, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/workflows/{workflow_id}/runs/{run_id}/approvals"); | ||
| let request = build_authed_request(&state.http_client, Method::GET, &path, &state)?; | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[derive(Serialize)] | ||
| struct ApprovalBody { | ||
| #[serde(skip_serializing_if = "Option::is_none")] | ||
| note: Option<String>, | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn grant_approval( | ||
| token: String, | ||
| note: Option<String>, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/approvals/{token}/grant"); | ||
| let request = build_authed_request(&state.http_client, Method::POST, &path, &state)? | ||
| .json(&ApprovalBody { note }); | ||
| send_json_request(request).await | ||
| } | ||
|
|
||
| #[tauri::command] | ||
| pub async fn deny_approval( | ||
| token: String, | ||
| note: Option<String>, | ||
| state: State<'_, AppState>, | ||
| ) -> Result<serde_json::Value, String> { | ||
| let path = format!("/api/approvals/{token}/deny"); | ||
| let request = build_authed_request(&state.http_client, Method::POST, &path, &state)? | ||
| .json(&ApprovalBody { note }); | ||
| send_json_request(request).await | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The new run-approvals response is serializing
ApprovalRecord.tokendirectly, but that field is the DB-stored hashed token (the raw token is hashed before insert insprout-db::workflow::create_approval). The UI then passes this value toPOST /api/approvals/{token}/grant|deny, which hashes the path token again for lookup, so approvals fetched from this endpoint cannot be granted/denied and will consistently fail as not found/conflict. This blocks the primary approval action flow added by this change.Useful? React with 👍 / 👎.