Add a sandboxed send-email.js workflow script with SMTP settings
exposed via script config and password loaded from named secrets.
Allow nodemailer in the script sandbox require whitelist.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
- Implemented revealHttpAuthLiterals function to return plaintext credential fields from HTTP auth configurations.
- Added a new endpoint in the HTTP auths API to reveal credentials securely.
- Updated the web interface to fetch and display plaintext literals, improving user experience for managing credentials.
- Enhanced CredentialFields component to support revealing and masking credential values dynamically.
- Introduced new HTTP authentication and page management APIs, allowing for the creation, retrieval, updating, and deletion of HTTP auth profiles and pages.
- Added validation for auth and page fields to ensure proper configuration and error handling.
- Implemented a mechanism for resolving auth credentials from various sources, including inline definitions, KV store, and secrets.
- Enhanced workflow validation to include checks for HTTP triggers, ensuring proper auth and response configurations.
- Updated the web interface to include new routes for managing HTTP auth profiles and pages, improving user experience and accessibility.
- Added a new KV store API with endpoints for querying namespaces and key-value pairs.
- Introduced fingerprinting functionality to hash and manage data fingerprints, allowing for efficient change detection.
- Enhanced existing scripts to utilize the new fingerprinting capabilities, enabling conditional execution based on data changes.
- Updated the web interface to include a dedicated KV page for managing key-value entries and displaying their details.
- Improved overall user experience with pagination and search capabilities in the KV management interface.
- Introduced a new script for fetching RSS feeds, allowing workflows to process and transform feed data using JSONata.
- Updated workflow configuration to include a new RSS feed script, enhancing the capabilities of existing workflows.
- Enhanced the workflow management API to support enabling and disabling workflows dynamically.
- Improved UI components to reflect the new workflow features, including enabling/disabling workflows and displaying their statuses.
- Added support for wildcard filtering in workflow queries, improving the flexibility of workflow management.
- Added support for triggering workflows via a new triggerWorkflow function, allowing for fire-and-forget execution of workflows with optional data transformation using JSONata.
- Introduced a $workflows API in the script sandbox for accessing workflow triggers.
- Enhanced existing script execution functions to accommodate the new workflow triggering capabilities.
- Updated workflow-mermaid.js and WorkflowsPage to reflect the new workflow type in labels for better clarity.
- Added SCRUNNER_SECRETS_KEY to README as a required variable for production.
- Implemented redaction of sensitive information in logs across various components.
- Enhanced script execution functions to include an owner parameter for better secret management.
- Introduced a secrets API in the script sandbox for retrieving and managing secrets.
- Updated UI components to support owner selection for script execution and secret management.
- Updated LogViewer component to accept filters and a callback for removing filters.
- Modified EventDetailPage to manage step filters, allowing users to filter logs based on selected steps.
- Added UI elements for displaying active filters and a button to toggle filtering for each step.
- Improved log visibility by applying filters dynamically based on user selection.
- Refactored step execution logic to introduce runCompiledStep for improved clarity and functionality.
- Added support for "set" steps, allowing context manipulation using JSONata expressions.
- Implemented evaluateJsonata and isJsonataTruthy functions for evaluating conditions and expressions.
- Updated workflow parsing to handle new step types and validation rules.
- Enhanced logging and error handling for skipped steps and invalid configurations.
- Modified UI components to reflect new step types and statuses, including "skipped".
- Introduced WorkflowNewPage and WorkflowEditPage for creating and editing workflows.
- Updated App component to include new routes for workflow management.
- Enhanced workflow diagram generation in workflow-mermaid.js for better visualization.
- Modified WorkflowsPage to support navigation to the new workflow pages.
- Improved HomePage links to direct users to the correct workflow edit paths.
- Introduced compileWorkflowScripts function to parse and validate workflow scripts, supporting both linear and DAG execution modes.
- Added runLinearSteps and runDagSteps functions for executing compiled workflows based on their structure.
- Updated createRegistry function to utilize the new workflow compilation and execution logic.
- Enhanced script sandbox with meta extraction and instantiation capabilities for better script management.
- Improved API endpoints to return script metadata and handle errors more effectively.
- Removed deprecated scripts and updated workflows to reflect new structure and functionality.
- Introduced a new dry-run endpoint for executing scripts without saving changes.
- Implemented a dedicated ScriptDryRunPage for user interaction with dry-run functionality.
- Enhanced ScriptsPage to support navigation to the dry-run feature.
- Added LogViewer component for displaying logs during script execution.
- Created ScriptEditPage for editing scripts with integrated dry-run capabilities.
- Updated workflows to include new scripts for fetching and notifying data.
- Improved overall user experience with better navigation and error handling.
- Added node-html-parser as a dependency for parsing HTML content.
- Implemented fetch-html script to fetch and parse HTML from a specified URL.
- Updated script sandbox to allow the use of node-html-parser.
- Created a new workflow for fetching data from dev.to, including configuration for URL and selectors.
- Updated package.json to include node-html-parser in server package dependencies.
- Introduced a new server package with Fastify for handling API requests and workflows.
- Implemented user authentication and authorization with JWT and cookie management.
- Added endpoints for managing workflows, runs, and user accounts.
- Established a dashboard for monitoring workflow status and statistics.
- Included a script sandbox for executing user-defined scripts securely.
- Updated README with setup instructions and API documentation.
- Configured database migrations for user management.
- Enhanced logging capabilities for better traceability.
- Added database configuration and migration setup using Knex.
- Implemented a logging system with Pino, including log persistence and flushing.
- Created a server runner with Fastify, integrating authentication and various API routes.
- Introduced a script sandbox for executing user-defined scripts with restricted access.
- Established initial workflows and scripts for manual and cron triggers.
- Included documentation for API endpoints and workflows.
Self-hosted automation targets often run on localhost or loopback
addresses, so keep blocking private/metadata hosts but stop blocking
localhost, 127.x.x.x, and .localhost names.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>