Skip to content

fix(resume): require write access to resume a paused run on the legacy route - #8896

Open
waleedlatif1 wants to merge 2 commits into
stagingfrom
fix/resume-post-write-authz
Open

waleedlatif1 wants to merge 2 commits into
stagingfrom
fix/resume-post-write-authz

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Legacy POST /api/resume/[workflowId]/[executionId]/[contextId] authorized through validateWorkflowAccess, which only checks workspace read, so a read-only member or their API key could answer a human-in-the-loop pause and continue the run with their own input
  • The route now authenticates with internalWorkflowSessionOrApiKeyAuth and runs resumeWorkflowRun, the same workflows.runs.resume operation (write role) the v2 resume route uses. It also gets the run-to-workflow scope check and cross-tenant concealment
  • resumeWorkflowRun takes the calling surface (legacy | v2), so the legacy route keeps streaming and job-id polling, and it forwards the request signal and headers that a streamed resume needs
  • Inlined the single-consumer resume-handler.ts presenter into the route. The GET detail handler keeps read access

Type of Change

  • Bug fix

Testing

  • Regression tests: a read-role member gets 403 from the legacy POST over session and personal-API-key auth, and nothing is enqueued. They go red when resumeRun is lowered to read
  • The use-case test asserts request signal/headers forwarding, and goes red when forwarding is removed
  • Ran [contextId]/route.test.ts, workflow-run-control.test.ts, and v2 resume/route.test.ts (35/35)
  • Ran bun run lint, check:api-validation:strict, check:boundaries, check:test-patterns, check:route-verbs, check:unused-exports, check:principal-kind-parity, check:utils, check:comment-hygiene

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

…y route

POST /api/resume/[workflowId]/[executionId]/[contextId] authorized with
validateWorkflowAccess, which checks workspace read permission, so a
read-only member (or their API key) could answer a human-in-the-loop pause
and continue the run with arbitrary input. The route now authenticates with
the internal workflow session/API-key policy and runs the resumeWorkflowRun
use case, the same write-role operation the v2 resume route uses.

resumeWorkflowRun takes the calling surface ('legacy' | 'v2') so the legacy
route keeps its streaming and job-id polling responses, and forwards the
request signal and headers a streamed resume needs.
@vercel

vercel Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 10, 2026 8:07pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 8 files

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/app/api/resume/[workflowId]/[executionId]/[contextId]/route.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge; no blocking issue was found.

Summary

The PR makes the legacy resume POST require write access through resumeWorkflowRun, while preserving streaming and job polling.

  • Legacy resume requests now need write access to continue a paused run.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  Legacy[Legacy resume POST] --> Auth[Authenticate caller]
  V2[V2 resume POST] --> Auth
  Auth --> UseCase[resumeWorkflowRun]
  UseCase --> Access[Check run scope and write access]
  Access --> Resume[executeResumeWorkflow]
  Resume --> Result[Return result for calling surface]
  UseCase -->|Unexpected error| Handler[Shared route handler]
  Handler --> Generic[Generic 500 response]
Loading

Reviews (2) · Last reviewed commit: "fix(resume): let unexpected resume failu..." · Reviewed by Greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 8 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — a53667e9 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant