Skip to content

fix(workflows): stop flagging whole-field references in JSON fields and correct the quoting advice - #8837

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/lint-unquoted-json-ref-false-positives
Oct 9, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/lint-unquoted-json-ref-false-positives

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • The unquoted-JSON-reference lint no longer flags a field made only of references (e.g. Response data or an API body set to <agent.content>). The block receives that text as-is: Response returns text it can't parse unchanged, API sends it as a raw body. Quoting it would only turn JSON text into a JSON string.
  • A reference inside JSON text ({"note": <agent.content>}, [<agent.content>]) still flags, as do the Table row cases.
  • Rewrote the advice. References are inserted raw and there's no JSON-aware escaping outside Function code, so quoting is only safe for text with no ", \ or line break (ids and the like). For free text it now says to build the JSON in a Function block and set the field to that block's result reference.
  • Deploy warnings come from the same lint report, so they pick this up unchanged.

Type of Change

  • Bug fix

Testing

  • New cases in json-literal-refs.test.ts: whole-field and references-only fields don't flag, references inside JSON still flag, advice text. The behavior tests fail on the previous code and pass now.
  • Probed against the real block registry: Response/API whole-field <agent.content> flagged before, clean after; API {"text": <agent.content>} and Table v2 Insert Row {"name": <agent.content>} flag both before and after.
  • bun run lint, bun run type-check, bun run check:audits, vitest on lib/workflows/editing, lib/workflows/application, executor/variables.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 5:26am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 2 files

Confidence score: 3/5

  • In apps/sim/lib/workflows/editing/lint.ts, the blanket exemption also covers table_v2.data and rows, whose handlers parse them as JSON, so malformed <agent.content> can still fail at runtime without a warning. Restrict the exemption to raw paths.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/workflows/editing/lint.ts">

<violation number="1" location="apps/sim/lib/workflows/editing/lint.ts:775">
P2: `table_v2.data` and `rows` also reach this helper, but their handlers parse them as JSON, so `<agent.content>` can still fail at runtime while this blanket exemption hides the warning. Restrict the exemption to raw pass-through fields such as `api.body` and `response.data`.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/workflows/editing/lint.ts Outdated
Comment thread apps/sim/lib/workflows/editing/lint.ts
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium impact] The changes since the previous review appear safe to merge.

Summary

The PR stops warning about reference-only JSON fields and gives safer advice for inserting text into JSON.

  • The latest changes add control characters to the quoting warning and update the matching test.
  • No new actionable issues or repository-rule violations were found.
  • No previous review threads were supplied. Tests were not run during this review.

Reviews (2) · Last reviewed commit: "fix(workflows): name JSON control charac..." · Reviewed by Greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 3c87849 into staging Oct 9, 2026
47 checks passed

This branch was previously deployed

1 inactive deployment
Preview — 7864d23c Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant