Repository navigation
fix(resume): require write access to resume a paused run on the legacy route - #8896
waleedlatif1 wants to merge 2 commits into
Conversation
…y route
POST /api/resume/[workflowId]/[executionId]/[contextId] authorized with
validateWorkflowAccess, which checks workspace read permission, so a
read-only member (or their API key) could answer a human-in-the-loop pause
and continue the run with arbitrary input. The route now authenticates with
the internal workflow session/API-key policy and runs the resumeWorkflowRun
use case, the same write-role operation the v2 resume route uses.
resumeWorkflowRun takes the calling surface ('legacy' | 'v2') so the legacy
route keeps its streaming and job-id polling responses, and forwards the
request signal and headers a streamed resume needs.
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
There was a problem hiding this comment.
All reported issues were addressed across 8 files
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Turn on auto-fix | Re-trigger cubic
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 8 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
Turn on auto-fix | Re-trigger cubic
Summary
POST /api/resume/[workflowId]/[executionId]/[contextId]authorized throughvalidateWorkflowAccess, which only checks workspace read, so a read-only member or their API key could answer a human-in-the-loop pause and continue the run with their own inputinternalWorkflowSessionOrApiKeyAuthand runsresumeWorkflowRun, the sameworkflows.runs.resumeoperation (write role) the v2 resume route uses. It also gets the run-to-workflow scope check and cross-tenant concealmentresumeWorkflowRuntakes the callingsurface(legacy|v2), so the legacy route keeps streaming and job-id polling, and it forwards the request signal and headers that a streamed resume needsresume-handler.tspresenter into the route. The GET detail handler keeps read accessType of Change
Testing
resumeRunis lowered toread[contextId]/route.test.ts,workflow-run-control.test.ts, and v2resume/route.test.ts(35/35)bun run lint,check:api-validation:strict,check:boundaries,check:test-patterns,check:route-verbs,check:unused-exports,check:principal-kind-parity,check:utils,check:comment-hygieneChecklist
test-auditauthoring gate)🤖 Generated with Claude Code