Skip to content

chore(release): staging to production - 2026.05.15 - #1076

Merged
ct3685 merged 1 commit into
productionfrom
staging
May 15, 2026
Merged

chore(release): staging to production - 2026.05.15#1076
ct3685 merged 1 commit into
productionfrom
staging

Conversation

@github-actions

Copy link
Copy Markdown

🚀 Release: Staging to Production

Release Date: 2026-05-15

Changes in this release


This PR is automatically created/updated when commits are pushed to staging.
Merging this PR will trigger the release workflow to create a new GitHub release.

…ate chatflow to Default Workspace (#1075)

## Root Cause

`getChatflowById` gates access by checking that `chatflow.workspaceId`
is in `req.user.assignedWorkspaces` (populated from explicit
`workspace_user` membership rows). This is correct for non-admins.

For admins, however, the template source chatflow (the row referenced by
`INITIAL_CHATFLOW_IDS`) was created with whatever `activeWorkspaceId`
the admin had at that moment — often a Personal Workspace or ad-hoc
workspace. That workspace isn't in another admin's `assignedWorkspaces`,
so they hit a misleading "chatflow not found" despite the row existing
in the DB.

## Changes

**`packages/server/src/controllers/chatflows/index.ts`**

Adds an admin bypass using the same `roles?.includes('Admin') ||
permissions?.includes('org:manage')` pattern used throughout the
codebase (documentstore, billing, organizations controllers). Admins
check org membership instead of workspace membership:

```typescript
const isAdmin = req.user?.roles?.includes('Admin') || req.user?.permissions?.includes('org:manage')
const hasWorkspaceAccess = isAdmin
    ? apiResponse.organizationId === req.user?.activeOrganizationId
    : apiResponse.workspaceId
      ? assignedWorkspaces.some((ws) => ws.id === apiResponse.workspaceId)
      : false
```

Non-admin workspace gate is unchanged.


**`packages/server/src/database/migrations/postgres/aai/1770000000003-FixTemplateSourceChatflowWorkspace.ts`**

Idempotent migration that moves each chatflow in `INITIAL_CHATFLOW_IDS`
/ `INITIAL_CHATFLOW_ID` to the Default Workspace of its organization, so
the template lives in a predictable shared location going forward. Only
moves chatflows that are NOT already in a Default Workspace.

## Test Plan

- [ ] As an admin, access a chatflow whose `workspaceId` is a Personal
Workspace the admin is not a direct member of — should now return the
chatflow
- [ ] As a non-admin, access a chatflow in a workspace they're not a
member of — should still return NOT_FOUND
- [ ] Run migration on staging DB — template chatflow moves to Default
Workspace
- [ ] Template chatflow already in Default Workspace — migration is a
no-op
- [ ] No `INITIAL_CHATFLOW_IDS` configured — migration logs skip and
exits cleanly
@vercel

vercel Bot commented May 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
answerai-docs Building Building Preview May 15, 2026 8:20pm
the-answerai Building Building Preview May 15, 2026 8:20pm

Request Review

@ct3685
ct3685 merged commit 3744c4c into production May 15, 2026
7 of 8 checks passed
@maxtechera
maxtechera temporarily deployed to staging - aai-unified2-flowise-moonstruck May 15, 2026 20:21 — with Render Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants