Repository navigation
Sync ako/mxcli: published REST authentication, tab pages in ALTER PAGE, check fixes - #1334
Merged
Merged
Conversation
`@excluded declare $Variable Boolean = false;` parsed and exec reported success, but the activity was written with Disabled = false, so DESCRIBE dropped @excluded and every round trip re-enabled disabled activities. flowBuilder.mergeStatementAnnotations copies ActivityAnnotations into the pending set field by field and never copied Excluded; parser, applyAnnotations, backend writer and describer were all already correct. A reflection test now sets every ActivityAnnotations field and asserts the merge keeps it (with an explicit allowlist for fields consumed elsewhere), so the next field added cannot be dropped the same way. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019qvyvuzR75HxuWwbtnoAd1
…ty value `create published rest service M.Api (…, Authentication: microflow M.F)` crashed check/exec with a nil pointer dereference in unquoteStringLit (mendixlabs#1331). Build walks a failed parse on purpose, so the property context arrived without its STRING_LITERAL child. unquoteStringLit now reads a nil node as "". That covers every call site, not only this rule: #1023 was the same class, guarded at one site. The author now gets `mismatched input 'microflow' expecting STRING_LITERAL`. Authentication support for published REST services, the issue's other half, is a separate feature and is not in this change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
A data container's widget-name variable is in scope only one data container below it, and that holds for every slot evaluated in a widget's enclosing context, not only action arguments. Measured on mxbuild 11.14.0, each against a control one data view deeper that builds clean: a nested widget's microflow data-source argument, Visible, Editable and DynamicClasses reading the container they sit in directly are CE0117, and a nested list's XPath `where` is CE0161. All five passed check and exec. checkOwnContainerName now takes the widget and walks its action arguments, data-source arguments and XPath, and those expression properties, naming the CE code per slot. Text-template parameters are left alone: MDL-WIDGET24 already refuses a variable path there. Refs mendixlabs#1324 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QLPboEFUCLXZr6qwX2T9LF
`describe structure depth 2|3` is meant to list each page's data widgets (`Page M.P [DataView<Customer>, ListView<Order>]`) and never did: the query filtered on a ParentWidget column that widgets_data has never had, and the error was discarded, so every page printed bare - from the initial commit on. - Query ParentWidgetId and list a page's outermost data widgets: those with no data widget above them. Filtering on the page root instead would list almost nothing, since real pages wrap content in a layout grid. Snippet widgets are excluded (ContainerType = 'PAGE'). - Built-in types print without their storage prefix (DataView, not Forms$DataView). - Route every catalog query in cmd_structure.go through structureQuery, which returns the error instead of discarding it. These are fixed SQL against tables the builder owns, so a failure is drift inside mxcli; swallowing it is what hid this bug and the depth-1 casing bug (#717). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…loop `change $T (...) commit;` or `create ... commit;` inside a loop is one database round trip per iteration, exactly like a separate `commit $T;`, and Studio Pro's recommender flags both (MXP004). CONV011 matched only CommitObjectsAction, and MDL-PERF01 — pinned to CONV011's boundary — inherited the gap. Both now treat any Commit value other than No on a CreateObjectAction / ChangeObjectAction as a commit. Control: with the fix reverted, `lint -r CONV011` on the bug-test project flags only SUB_CloseAll2 (the reported symptom); fixed, it flags SUB_CloseAll, SUB_CloseAll2 and SUB_LogAll, and not the commit-after-loop control. Fixes upstream mendixlabs#1217 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LNT3XFXcwnQa4hv4RfzQ8j
…endixlabs#1216) `check -p` rejected `parseDateTimeUTC($Text, 'yyyy-MM-dd', empty)` with "parseDateTimeUTC() expects 2 argument(s), got 3. [E006]", and exec refused it, while mx check on 11.14.0 reports 0 errors. funcTable had the parse functions fixed at their minimum arity. Widened only what mx check 11.14.0 accepts, each case built in its own project copy: parseDateTime / parseDateTimeUTC (value, format [, default]) parseInteger (value [, default]) parseDecimal (value [, format [, default]]) parseBoolean($s, false) and the 4-argument forms are CE0117 there and keep firing E006. Fixes mendixlabs#1216 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015L6AvbQGMGtGDjRKQcTyxa
…ixlabs#1215) `insert after <tabpage> { tabpage … }` and `insert into <tabcontainer> { tabpage … }` both failed with "tabpage must be a direct child of tabcontainer": an INSERT built its nodes one by one, and the builder only builds a tab page as a tab container's child. A Forms$TabPage is also not a widget — it lives in the control's TabPages list — so it now takes its own path, as list view templates and DataGrid2 columns do: - executor routes an all-tabpage INSERT to buildTabPagesFromAST and a new PageMutator.InsertTabPages; a mixed tabpage/widget INSERT is refused - the mutator appends for INTO a tab container, splices next to the sibling for BEFORE/AFTER a tab page, refuses any other target, keeps the control's DefaultPagePointer (setting it only on an empty control), and serializes the pages through the codec by wrapping them in a throwaway tab container Verified on Mendix 11.14.0: the issue's script plus `insert before`, then `mxcli docker check` → 0 errors; with the page forced into the sibling's Widgets mx cannot load the project. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ti2KVU7Vfs1PjqF5TorcyN
…tures `check --references` passed a declared type naming an entity that does not exist: a microflow/nanoflow/rule parameter or return type (`$p: System.Nope`, `$p: M.Nope`, `list of System.Nope`, `returns System.Nope`) and a page/snippet parameter. The body of a flow, an association's endpoints and an EXTENDS target were resolved; the signature never was. exec refuses the user-module shapes and every page/snippet parameter after the statements before it are written; a System entity in a flow signature it writes by name, leaving a dangling reference. Resolution goes through buildEntityQualifiedNames, which lists the virtual System domain model, so System.User resolves and System.Nope does not. A bare Module.Name is accepted as an entity or an enumeration (System.DeviceType); a backend that lists no System module at all is not taken as evidence that a System entity is missing. The originally reported shape, `create association … from System.Nope`, is already refused on main (#555); it is kept as a regression case. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(microflow): keep @excluded on activities (mendixlabs#1328)
fix(structure): annotate pages with their data widgets at depth 2 and 3
…L044 at the token funcTable listed `currentDateTime` as a built-in, and funcTable is MDL044's only allow-list, so `declare $D DateTime = currentDateTime();` passed check and exec. mx check on 11.14.0 then failed it, in a microflow and a nanoflow alike: [error] [CE0117] "Error(s) in expression." at Create variable activity 'Create Date and time variable' The current time is the [%CurrentDateTime%] token, which builds at 0 errors in both. This removes the entry and gives MDL044 a token hint (FuncRef.Token, from exprcheck.tokenFuncs). A spelling-based did-you-mean cannot point to a token. Found while measuring mendixlabs#1216, where a currentDateTime() default made the 3-argument parseDateTime look invalid. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015L6AvbQGMGtGDjRKQcTyxa
The storage measured on ako/TestApp, one service per dialog state: "no authentication" is the empty list, unticking Custom clears the microflow, and the list keeps the order the methods were ticked. Syntax follows R9: an `Authentication:` property, settable through `alter … set ( … )`. For mendixlabs#1331. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
Support INSERT of tab pages into tab containers (mendixlabs#1215)
`Authentication: none | ( basic, session, microflow M.F )` on `create [or modify] published rest service`, and `alter … set ( … )` taking create's property list (R3). Methods are written in the order given and described in the stored order: Studio Pro stores them in the order they were ticked (ako/TestApp), so sorting would rewrite an unchanged service. Unstated, create-or-modify and alter keep the stored setting. The two fields move from the writer's carry-the-stored-bytes list to the model, so the executor now carries an unstated setting; a test pins that carry, which had no test while the writer did it (#571). The authentication microflow is checked as MDL-REST04 by exec and check --references: it returns System.User and takes only a System.HttpRequest and/or System.HttpResponse, matched by type — CE0334 and CE0336, measured with mx check on 11.14.0. describe → exec of each of TestApp's four Studio Pro services writes no unit; reordering the methods on one rewrites exactly that unit. For mendixlabs#1331. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
MDL-BUTTON02: also flag own-container names in data sources and widget expressions
Fix expression checker: parse-function default argument (mendixlabs#1216), and currentDateTime() is not a built-in
Fix CONV011 to detect commit clause on create/change in loops
Fix nil pointer panic in unquoteStringLit for non-string property values
Resolves the findings-file conflict GitHub reports: both sides appended to mdl-executor.jsonl, which merge=union keeps locally but GitHub's server-side merge does not. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
feat(rest): authentication on a published REST service
fix(check): --references resolves entity types in flow and page signatures
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Syncs
ako/mxcli:mainintomendixlabs/mxcli:main: 11 commits since #1332, landed in the fork through PRs ako#1015–#1026.Published REST
Authentication: none | ( basic, session, microflow M.F )oncreate [or modify] published rest service, andalter … set ( … )taking create's property list (Published REST service: no way to set authentication; a non-string property value (e.g. Authentication: microflow M.F) panics the parser (visitor_rest.go) #1331). Storage was measured on Studio Pro: methods keep the order they were ticked, and an unstated setting is carried on create-or-modify and alter. MDL-REST04 checks the authentication microflow's signature (CE0334). A design proposal is included.unquoteStringLit, so it covers every call site.Pages
insert into <tabcontainer>orinsert before|after <tabpage>, keeping the default page. Verified on 11.14.0.Microflows
@excludedis kept on activities (@excluded on microflow activities does not seem to work anymore #1328). It parsed but was written as enabled, so every round trip re-enabled disabled activities. A reflection test makes the next annotation field impossible to drop the same way.Check / lint
check --referencesresolves entity types in flow and page signatures: parameter and return types, includingSystem.*.parseDateTimeUTC($t, 'yyyy-MM-dd', empty)(check E006 false positive: parseDateTimeUTC() with a default value (3 arguments) is rejected, but Mendix accepts it (mx check 0 errors) #1216). This is widened only to what mx check 11.14.0 accepts.currentDateTime()is not a Mendix function. MDL044 now flags it and points at the[%CurrentDateTime%]token (CE0117 before).create … commitandchange … commitinside a loop as a commit in a loop, as Studio Pro's recommender does (Lint CONV011 (NoCommitInLoop) misses CHANGE … COMMIT (and CREATE … COMMIT) inside a loop; only a separate COMMIT activity is flagged #1217).Describe
describe structure depth 2|3annotates pages with their outermost data widgets, which it never did. A broken query's error was being discarded