Skip to content

feat(resource-policies): add statement evaluator - #6892

Open
TheodoreSpeaks wants to merge 9 commits into
feat/workspace-principalfrom
feat/credential-group-resource-policies
Open

feat(resource-policies): add statement evaluator#6892
TheodoreSpeaks wants to merge 9 commits into
feat/workspace-principalfrom
feat/credential-group-resource-policies

Conversation

@TheodoreSpeaks

@TheodoreSpeaks TheodoreSpeaks commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • replace credential group grants with statement-based resource policies supporting explicit allow/deny and bounded IAM-style conditions
  • bind persisted execution principals and current workflow authority into credential-use decisions, while keeping actor-owned credential access as a hidden system rule
  • add a raw JSON policy editor plus trigger-owned policy lifecycle and a bounded backfill

Type of Change

  • New feature

Testing

  • bun run lint
  • bun run type-check
  • bun run check:audits
  • bun run check:migrations origin/staging
  • 67 database tests and 221 focused application/workflow tests

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Aug 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Ready Ready Preview Aug 26, 2026 4:27am

Request Review

@cursor

cursor Bot commented Aug 20, 2026

Copy link
Copy Markdown

PR Summary

High Risk
Changes authorization for managed OAuth credentials and internal executor delegation, including policy evaluation, deployment-version binding, and token issuance. Mis-evaluation could over- or under-grant credential access.

Overview
Replaces enrollment-only Credential Group token checks with stored IAM-style resource policies (allow/deny, principals, flat conditions) plus a hidden actor-own system rule. Admins can edit the full policy as JSON; credential use is policy-gated while listing stays discovery-only.

Adds a required per-group policy lifecycle (create/delete/backfill), optimistic-concurrency admin GET/PUT, and a settings Access tab. Credential use now evaluates credential_groups.credentials.use with explicit-deny precedence.

Threads current workflow (draft vs active deployment version) through executor delegation and child-workflow execution so workflow principals and sim:WorkflowMode conditions bind to the child, not the root. Deployed state APIs now require deploymentVersionId; stale or cross-workspace child authority fails closed.

Reviewed by Cursor Bugbot for commit a01a557. Bugbot is set up for automated code reviews on this repo. Configure here.

@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch from 9995853 to 0c9fb23 Compare August 20, 2026 18:12
@greptile-apps

greptile-apps Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

The PR replaces credential-group grants with revisioned statement-based resource policies and propagates execution authority into credential-use decisions.

  • Adds credential-group access management APIs and settings UI.
  • Adds policy persistence, lifecycle triggers, migration, backfill, and reconciliation tooling.
  • Carries workflow deployment identity and originating principals through delegated and resumed execution paths.

Confidence Score: 5/5

The PR appears safe to merge because no blocking failure remains.

No blocking failure remains.

Important Files Changed

Filename Overview
apps/sim/lib/credential-groups/application/authorization.ts Enforces executor-principal, workflow-authority, enrollment, and resource-policy checks before credential-group credential use.
apps/sim/lib/credential-groups/application/workflow-access-policy.ts Defines and evaluates the bounded workflow-only policy document with deployment-mode enforcement and deny-by-default behavior.
apps/sim/lib/auth/internal-delegation.ts Binds delegated executor claims to canonical execution, workflow, workspace, and deployment-version context.
apps/sim/lib/resource-policies/repository.ts Adds revisioned policy reads and transactionally guarded optimistic updates.
packages/db/credential-group-resource-policies.ts Implements credential-group policy lifecycle triggers, bounded backfill batches, and relational-invariant validation.
apps/sim/ee/credential-groups/components/credential-group-access.tsx Adds a revision-aware workflow-access editor that preserves drafts across refreshes and validates catalog availability before saving.
apps/sim/lib/workflows/executor/execution-core.ts Propagates current deployed-workflow authority through workflow execution and resume boundaries.

Sequence Diagram

sequenceDiagram
  participant Admin
  participant AccessAPI
  participant PolicyStore
  participant Executor
  participant Delegation
  participant CredentialAuth

  Admin->>AccessAPI: Select allowed workflows
  AccessAPI->>PolicyStore: Write policy with expected revision
  PolicyStore-->>AccessAPI: New revision
  Executor->>Delegation: Bind principal and deployed workflow authority
  Delegation->>CredentialAuth: Resolve managed credential
  CredentialAuth->>PolicyStore: Read credential-group policy
  PolicyStore-->>CredentialAuth: Policy document
  CredentialAuth->>CredentialAuth: Evaluate actor rule and workflow statements
  CredentialAuth-->>Executor: Allow credential or deny safely
Loading

Reviews (5): Last reviewed commit: "improvement(credential-groups): simplify..." | Re-trigger Greptile

Comment thread apps/sim/ee/credential-groups/components/credential-group-access.tsx Outdated
@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch from aaea6ae to 52e3168 Compare August 21, 2026 00:17
@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch 2 times, most recently from 95eafd9 to 9d5f513 Compare August 21, 2026 01:41
@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch 2 times, most recently from c2d891e to 64f547f Compare August 21, 2026 01:53
Comment thread packages/db/migrations/0298_sparkling_hemingway.sql
Comment thread apps/sim/lib/credential-groups/application/manage-access.ts
@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch from 64f547f to eccb03a Compare August 21, 2026 04:47
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cursor review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

3 issues from previous reviews remain unresolved.

Fix All in Cursor

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit eccb03a. Configure here.

@TheodoreSpeaks
TheodoreSpeaks force-pushed the feat/credential-group-resource-policies branch from eccb03a to ede2aba Compare August 21, 2026 05:07
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cursor review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

There are 5 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit ede2aba. Configure here.

Comment thread apps/sim/hooks/queries/credential-groups.ts
Comment thread apps/sim/lib/api/contracts/credential-groups.ts
@TheodoreSpeaks TheodoreSpeaks changed the title feat(credential-groups): add resource access policies feat(resource-policies): add statement evaluator Aug 23, 2026
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cursor review

@cursor

cursor Bot commented Aug 25, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@TheodoreSpeaks
TheodoreSpeaks requested a review from a team as a code owner August 26, 2026 04:22
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cursor review

@cursor

cursor Bot commented Aug 26, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant