Skip to content

Sync ako/mxcli: published REST authentication, tab pages in ALTER PAGE, check fixes - #1334

Merged
ako merged 26 commits into
mendixlabs:mainfrom
ako:main
Oct 7, 2026
Merged

ako merged 26 commits into
mendixlabs:mainfrom
ako:main

Conversation

@ako

@ako ako commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Syncs ako/mxcli:main into mendixlabs/mxcli:main: 11 commits since #1332, landed in the fork through PRs ako#1015–#1026.

Published REST

Pages

Microflows

Check / lint

Describe

  • describe structure depth 2|3 annotates pages with their outermost data widgets, which it never did. A broken query's error was being discarded

claude and others added 26 commits October 7, 2026 09:36
`@excluded declare $Variable Boolean = false;` parsed and exec reported
success, but the activity was written with Disabled = false, so DESCRIBE
dropped @excluded and every round trip re-enabled disabled activities.

flowBuilder.mergeStatementAnnotations copies ActivityAnnotations into the
pending set field by field and never copied Excluded; parser, applyAnnotations,
backend writer and describer were all already correct.

A reflection test now sets every ActivityAnnotations field and asserts the
merge keeps it (with an explicit allowlist for fields consumed elsewhere), so
the next field added cannot be dropped the same way.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019qvyvuzR75HxuWwbtnoAd1
…ty value

`create published rest service M.Api (…, Authentication: microflow M.F)`
crashed check/exec with a nil pointer dereference in unquoteStringLit
(mendixlabs#1331). Build walks a failed parse on purpose, so the
property context arrived without its STRING_LITERAL child.

unquoteStringLit now reads a nil node as "". That covers every call site,
not only this rule: #1023 was the same class, guarded at one site. The
author now gets `mismatched input 'microflow' expecting STRING_LITERAL`.

Authentication support for published REST services, the issue's other
half, is a separate feature and is not in this change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
A data container's widget-name variable is in scope only one data
container below it, and that holds for every slot evaluated in a
widget's enclosing context, not only action arguments. Measured on
mxbuild 11.14.0, each against a control one data view deeper that
builds clean: a nested widget's microflow data-source argument,
Visible, Editable and DynamicClasses reading the container they sit in
directly are CE0117, and a nested list's XPath `where` is CE0161. All
five passed check and exec.

checkOwnContainerName now takes the widget and walks its action
arguments, data-source arguments and XPath, and those expression
properties, naming the CE code per slot. Text-template parameters are
left alone: MDL-WIDGET24 already refuses a variable path there.

Refs mendixlabs#1324

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QLPboEFUCLXZr6qwX2T9LF
`describe structure depth 2|3` is meant to list each page's data widgets
(`Page M.P [DataView<Customer>, ListView<Order>]`) and never did: the
query filtered on a ParentWidget column that widgets_data has never had,
and the error was discarded, so every page printed bare - from the
initial commit on.

- Query ParentWidgetId and list a page's outermost data widgets: those
  with no data widget above them. Filtering on the page root instead
  would list almost nothing, since real pages wrap content in a layout
  grid. Snippet widgets are excluded (ContainerType = 'PAGE').
- Built-in types print without their storage prefix (DataView, not
  Forms$DataView).
- Route every catalog query in cmd_structure.go through structureQuery,
  which returns the error instead of discarding it. These are fixed SQL
  against tables the builder owns, so a failure is drift inside mxcli;
  swallowing it is what hid this bug and the depth-1 casing bug (#717).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…loop

`change $T (...) commit;` or `create ... commit;` inside a loop is one
database round trip per iteration, exactly like a separate `commit $T;`,
and Studio Pro's recommender flags both (MXP004). CONV011 matched only
CommitObjectsAction, and MDL-PERF01 — pinned to CONV011's boundary —
inherited the gap. Both now treat any Commit value other than No on a
CreateObjectAction / ChangeObjectAction as a commit.

Control: with the fix reverted, `lint -r CONV011` on the bug-test
project flags only SUB_CloseAll2 (the reported symptom); fixed, it flags
SUB_CloseAll, SUB_CloseAll2 and SUB_LogAll, and not the commit-after-loop
control.

Fixes upstream mendixlabs#1217

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LNT3XFXcwnQa4hv4RfzQ8j
…endixlabs#1216)

`check -p` rejected `parseDateTimeUTC($Text, 'yyyy-MM-dd', empty)` with
"parseDateTimeUTC() expects 2 argument(s), got 3. [E006]", and exec refused
it, while mx check on 11.14.0 reports 0 errors. funcTable had the parse
functions fixed at their minimum arity.

Widened only what mx check 11.14.0 accepts, each case built in its own
project copy:
  parseDateTime / parseDateTimeUTC (value, format [, default])
  parseInteger (value [, default])
  parseDecimal (value [, format [, default]])
parseBoolean($s, false) and the 4-argument forms are CE0117 there and keep
firing E006.

Fixes mendixlabs#1216

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015L6AvbQGMGtGDjRKQcTyxa
…ixlabs#1215)

`insert after <tabpage> { tabpage … }` and `insert into <tabcontainer> { tabpage … }`
both failed with "tabpage must be a direct child of tabcontainer": an INSERT built
its nodes one by one, and the builder only builds a tab page as a tab container's
child. A Forms$TabPage is also not a widget — it lives in the control's TabPages
list — so it now takes its own path, as list view templates and DataGrid2 columns
do:

- executor routes an all-tabpage INSERT to buildTabPagesFromAST and a new
  PageMutator.InsertTabPages; a mixed tabpage/widget INSERT is refused
- the mutator appends for INTO a tab container, splices next to the sibling for
  BEFORE/AFTER a tab page, refuses any other target, keeps the control's
  DefaultPagePointer (setting it only on an empty control), and serializes the
  pages through the codec by wrapping them in a throwaway tab container

Verified on Mendix 11.14.0: the issue's script plus `insert before`, then
`mxcli docker check` → 0 errors; with the page forced into the sibling's Widgets
mx cannot load the project.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ti2KVU7Vfs1PjqF5TorcyN
…tures

`check --references` passed a declared type naming an entity that does not
exist: a microflow/nanoflow/rule parameter or return type
(`$p: System.Nope`, `$p: M.Nope`, `list of System.Nope`, `returns System.Nope`)
and a page/snippet parameter. The body of a flow, an association's endpoints
and an EXTENDS target were resolved; the signature never was.

exec refuses the user-module shapes and every page/snippet parameter after
the statements before it are written; a System entity in a flow signature it
writes by name, leaving a dangling reference.

Resolution goes through buildEntityQualifiedNames, which lists the virtual
System domain model, so System.User resolves and System.Nope does not. A bare
Module.Name is accepted as an entity or an enumeration (System.DeviceType);
a backend that lists no System module at all is not taken as evidence that a
System entity is missing.

The originally reported shape, `create association … from System.Nope`, is
already refused on main (#555); it is kept as a regression case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(structure): annotate pages with their data widgets at depth 2 and 3
…L044 at the token

funcTable listed `currentDateTime` as a built-in, and funcTable is MDL044's
only allow-list, so `declare $D DateTime = currentDateTime();` passed check
and exec. mx check on 11.14.0 then failed it, in a microflow and a nanoflow
alike:

  [error] [CE0117] "Error(s) in expression." at Create variable activity
  'Create Date and time variable'

The current time is the [%CurrentDateTime%] token, which builds at 0 errors
in both. This removes the entry and gives MDL044 a token hint
(FuncRef.Token, from exprcheck.tokenFuncs). A spelling-based did-you-mean
cannot point to a token.

Found while measuring mendixlabs#1216, where a currentDateTime() default made the
3-argument parseDateTime look invalid.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015L6AvbQGMGtGDjRKQcTyxa
The storage measured on ako/TestApp, one service per dialog state: "no
authentication" is the empty list, unticking Custom clears the microflow,
and the list keeps the order the methods were ticked. Syntax follows R9:
an `Authentication:` property, settable through `alter … set ( … )`.

For mendixlabs#1331.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
Support INSERT of tab pages into tab containers (mendixlabs#1215)
`Authentication: none | ( basic, session, microflow M.F )` on
`create [or modify] published rest service`, and `alter … set ( … )`
taking create's property list (R3). Methods are written in the order
given and described in the stored order: Studio Pro stores them in the
order they were ticked (ako/TestApp), so sorting would rewrite an
unchanged service. Unstated, create-or-modify and alter keep the stored
setting.

The two fields move from the writer's carry-the-stored-bytes list to the
model, so the executor now carries an unstated setting; a test pins that
carry, which had no test while the writer did it (#571).

The authentication microflow is checked as MDL-REST04 by exec and
check --references: it returns System.User and takes only a
System.HttpRequest and/or System.HttpResponse, matched by type — CE0334
and CE0336, measured with mx check on 11.14.0.

describe → exec of each of TestApp's four Studio Pro services writes no
unit; reordering the methods on one rewrites exactly that unit.

For mendixlabs#1331.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M7kpwBjefUzJwfyembWZKh
MDL-BUTTON02: also flag own-container names in data sources and widget expressions
Fix expression checker: parse-function default argument (mendixlabs#1216), and currentDateTime() is not a built-in
Fix CONV011 to detect commit clause on create/change in loops
Fix nil pointer panic in unquoteStringLit for non-string property values
Resolves the findings-file conflict GitHub reports: both sides appended to
mdl-executor.jsonl, which merge=union keeps locally but GitHub's
server-side merge does not.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
feat(rest): authentication on a published REST service
fix(check): --references resolves entity types in flow and page signatures
@ako
ako merged commit 20a6c89 into mendixlabs:main Oct 7, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants