From 250c71cfcc4a41622a2f2bdc77b11d2911691d57 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Tue, 21 Jul 2026 09:50:19 -0400 Subject: [PATCH] WES docs: tighten gxworkflow accessibility wording --- doc/source/dev/ga4gh_wes.md | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/doc/source/dev/ga4gh_wes.md b/doc/source/dev/ga4gh_wes.md index bd26d26e698..1b527e894a4 100644 --- a/doc/source/dev/ga4gh_wes.md +++ b/doc/source/dev/ga4gh_wes.md @@ -180,13 +180,14 @@ gxworkflow:// # the StoredWorkflow (latest versi gxworkflow://?instance=true # a specific Workflow instance ``` -The workflow just has to be accessible to the caller — the same rule a normal invocation +The workflow only has to be accessible to the caller — the same rule a normal invocation uses: owned by them, shared with them, published/importable, or the caller is an admin. -Otherwise you get a 403. With `gxworkflow://`, Galaxy skips -import and invokes the stored workflow directly. `workflow_type` is still required by the -form but is **not** validated against the stored workflow in this case — the -"must match the auto-detected type or 400" check only applies to inline -`workflow_attachment` / fetched `workflow_url` submissions. +Anything else is a 403. + +With `gxworkflow://`, Galaxy skips the import step and invokes the referenced workflow +directly. `workflow_type` is still required by the form but is **not** validated against +the stored workflow in this case — the "must match the auto-detected type or 400" check +only applies to inline `workflow_attachment` / fetched `workflow_url` submissions. ## 3. Submit the run