GGitHubfix: vulns (#7725)
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
feat: scheduled functions can execute (#7563) I decided to rollback some earlier decision where function and scheduled functions would be seen as separate entities in orchestrator. Now instead, there are represented as the same entity (with an optional logId and variant). Everything else in the payload (connection, functionId, integration) is an invariant and doesn't change between the moment the schedule is set and the creation/execution of the task. The cost of having optional attributes (logId and variant) is greatly compensated by having a single concept of function in the orchestrator. It is technically a breaking change but since there are still no scheduled functions in prod it is ok to merge and deploy it. <!-- Describe the problem and your solution --> <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7563?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 16 天前 | |
feat: introduces the orchestra API and client (#2162) ## Describe your changes Stage 2 of the orchestration v2: introducing the `orchestra` service. The orchestra is a new service that is running the scheduler and expose the API (via a client) to execute webhooks/actions, schedule syncs (TBA), and fetch queued tasks (TBD) Note: I am making heavy use of the `Endpoint` interface introduce by Samuel a few weeks ago. It is a bit more complicated to understand but it provides an easy way to implement type safe express endpoint. Let me know what you think. It is currently not wired and not running, next steps are: - add/modify the infra to run the service in prod and staging - add dequeuing task capabilities and task status reporting in the orchestra client - wire the orchestra service in the server so tasks are created for webhook and actions (behind flag) - wire the orchestra service in jobs so tasks are processed ## Checklist before requesting a review (skip if just adding/editing APIs & templates) - [X] I added tests, otherwise the reason is: - [ ] I added observability, otherwise the reason is: - [ ] I added analytics, otherwise the reason is: | 2 年前 | |
fix: vulns (#7725) ## Summary - Bump direct dependencies with published advisories: `undici` 6.29.0, `nodemailer` 10.0.13, `vitest` 4.1.11, `@vitest/browser-playwright` 4.1.11, `qs` 6.16.0, `multer` 2.4.0, `@elastic/elasticsearch` 8.19.2, and `testcontainers` 12.2.0. - Pin transitive `joi` to 17.13.8 and `valibot` to 1.5.0 with root overrides. `simple-oauth2` and Storybook keep their own declared ranges. - Refresh the lockfile for the other semver-compatible audit fixes, including the high `brace-expansion` finding. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7725?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 4 天前 | |
feat(auth): internal service auth (#7167) Optional Bearer auth between internal services (orchestrator and jobs). Off by default; existing deploys are unchanged until operators set secrets and flip `NANGO_INTERNAL_AUTH_REQUIRED`. ## Summary - Orchestrator and jobs HTTP APIs accept `Authorization: Bearer`, except `GET /health`. - Control plane (server, jobs, orchestrator) uses a shared static token (`NANGO_INTERNAL_AUTH_TOKEN`). - Jobs mints HMAC JWTs for runners: task-bound for `putTask`/`heartbeat`, node-bound for register/idle. The signing key stays on jobs; runners never receive `NANGO_INTERNAL_AUTH_TOKEN` or `NANGO_INTERNAL_AUTH_SIGNING_KEY`. Rollout plan [here](https://linear.app/nango/issue/NAN-6634/add-internal-auth-middleware-to-orchestrator-and-jobs#zero-downtime-rollout-2e12b4cc) --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 1 个月前 |