Treat in-progress connections (no target yet) as valid so React Flow can complete handle-to-handle links, and enlarge step handles.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add a Graph tab (React Flow) as the default workflow editor view, drop the Mermaid YAML preview, auto-assign step-N ids on add, and show test results as a JSON tree.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Profiles store script + default config per owner. Workflow steps reference
them with profile:, overlay keys win, and the UI marks overrides. Profile
name is immutable after create so YAML refs stay stable.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Extend GET /api/runs with offset/total, date and trigger filters,
and configurable column sort. Rebuild Events page with URL-driven state
matching the KV page pagination pattern.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
- Store up to 50 revisions per workflow in SQLite with normalized SHA dedup
- Soft-delete workflows to trash (7-day retention) with restore and permanent purge
- Assign UUID filenames for new and duplicated workflows; show name + file in UI
- Warn on invalid YAML, unknown scripts, and plaintext secrets with save-anyway option
- Add workflow backup zip (workflows + plugins) and merge/replace restore
- Trash page, history panel on editor, and smoke test
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Introduce plugin/<id> installs (zip, HTTPS git, example, fork),
jerapah-plugin.json manifests with jerapah semver ranges, isolated
plugin dirs under data/plugins, and app version 0.1.0. Core scripts
are non-editable; get-current-time moves to examples/plugins.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Vite listens on 8500 and proxies /ops to the control plane. Admin Ops UI
covers pause/resume, scale, drain/force restart, and restart-needed banner.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Wire optional REDIS_PASS into the BullMQ ioredis connection, redact
credentials in startup logs, and document REDIS_PASS plus JFLOW_ROLE.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Enqueue HTTP, cron, and manual runs via Redis/BullMQ; workers execute
asynchronously with configurable concurrency. Triggers return 202 and
clients poll GET /api/runs/:id for progress (queued → running → done).
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add HTML template kind to Responses with a seeded system email-default
template, render-template.js using Mustache, and html body support in
send-email. Templates are editable but system pages cannot be deleted.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Expose broader nodemailer transport options, require a separate from
address, and support optional cc/bcc plus reply-to and custom headers.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add a sandboxed send-email.js workflow script with SMTP settings
exposed via script config and password loaded from named secrets.
Allow nodemailer in the script sandbox require whitelist.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Self-hosted automation targets often run on localhost or loopback
addresses, so keep blocking private/metadata hosts but stop blocking
localhost, 127.x.x.x, and .localhost names.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>