The workflow tool understands run-based commands that bypass the usual allow and deny rule lookup.
Run operations with put, retract and read are recognised but the surrounding mode is not reachable.
What's wrong with this entry?
The workflow tool now recognises a second input shape carrying a run id plus one of put, retract or read. For those requests, permission checking skips the usual lookup of allow and deny rules by workflow name.
- An auto-classifier hook is consulted before anything else for these run operations, but the function supplying it returns undefined unconditionally in this build, so that path never contributes a decision.
runOpClassifierInput
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.246
Workflow pattern-matching words and a budget-starvation protocol
Both mention workflow
-
v2.1.246
Internal fact store gains variable binding, threshold triggers and budgets
Both mention workflow
-
v2.1.247
Workflow agents are cut off when they run past their token ceiling
Both mention workflow