Repository navigation
feat(definitions): reject publish when allowedAssemblies don't resolve - #1069
Conversation
…yCatalog Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…components Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…vailable assembly Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…heck Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
◈ PR Lens
Architecture 3 components touched across 4 lanes. Play the interactive walkthrough Inside the changed components — 1 viewComponent view — Publish validation Publish-time verification of allowed script assemblies in component definitions. Data flow
Follow each request, response and payload View
Tip Open a diagram on the canvas, then press W or click play to walk through the change one step at a time 🪧 More tips
Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| C# | Oct 2, 2026 2:41p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|


Summary
scripts.allowedAssemblies(at flow level or on any script slot) is now checked at publish time: every listed simple assembly name must resolve in the publishing runtime, either as a framework (TPA) assembly or as a DLL inScripting:Sandbox:PluginDirectory.SandboxedReferenceSet.Build, and the script only failed mid-transition with CS0012/CS1069 (e.g. a child reaching its final state but ending FAULTED). Now the publish returns 400, and the error names the exact field, e.g.sys-flows.states[0].onEntries[1].mapping.scripts.allowedAssemblies[0].helpers/REF references are not resolved, and a script that needs an assembly it never declares still fails only at run time.Changes
modules/.../Sandbox/SandboxedReferenceSet.cs: newIsResolvable(options, name)over the same cached TPA and plugin mapsBuilduses, so publish and compile share one resolution rule.modules/.../Sandbox/IScriptAssemblyCatalog.cs,SandboxScriptAssemblyCatalog.cs: the abstraction validators depend on.src/.../Definitions/Validators/AllowedAssembliesPublishCheck.cs: a component-agnostic walk over the publishedattributesJSON. It only looks atscriptsobjects whoseallowedAssembliesis a string array, and only forsys-flows,sys-tasks,sys-functionsandsys-extensions. It reports one error per unresolvable name.ComponentValidatorProcessor.Validateruns the check after the type-specific validator;TryValidate(seed data) is untouched. The catalog is registered inAddComponentValidatorsand falls back to default sandbox options on read-only hosts.docs/custom-script-helpers.md,vnext-meta/migrations.json(publish-rejects-unavailable-allowed-assemblies, since 0.0.98).Test Plan
SandboxScriptAssemblyCatalogTests7/7: framework name, case-insensitivity,.dllsuffix, empty/whitespace, plugin-directory DLL.AllowedAssembliesPublishCheckTests13/13: flow-level, nested slot path, one error per name, look-alike non-array ignored, scanned component types.ComponentValidatorProcessorTests11/11: the check fails a component the type validator passed; an out-of-scope type and seed data are not scanned.dotnet build vnext.sln: 0 errors.BBT.Workflow.Application.Tests: the 17 failing tests also fail on base3fc16d3c.SubflowDescentTracingTests(2) fails only in some full parallel runs and passes 12/12 when run alone, on both this branch and base.BBT.Workflow.Domain.Tests: 22 failing tests, the same 22 on base3fc16d3c.DefinitionController.PublishAsync→FromResult→WorkflowResultActionResultMapper, withValidationErrors[].Members) was verified by reading the code only.Notes
Scripting:Sandbox:Enabled=falsethe compiler ignores the per-script grant, so a stale or misspelled name used to be harmless. The publish check runs regardless of that flag, so such a package now gets 400 on its next publish. Fix: remove the name, use the simple name without.dll, or have the assembly mounted. This is recorded invnext-meta/migrations.json.allowedAssemblies(vnext-exampleaccount-opening:System.Security.Cryptography, a framework assembly), and it passes.vnext-meta/deprecations.jsonis invalid JSON on master (line 168).🤖 Generated with Claude Code