Skip to content

fix: emit grant execute in describe nanoflow - #1350

Closed
kris-bom wants to merge 1 commit into
mendixlabs:mainfrom
kris-bom:fix/36-nanoflow-grants
Closed

kris-bom wants to merge 1 commit into
mendixlabs:mainfrom
kris-bom:fix/36-nanoflow-grants

Conversation

@kris-bom

@kris-bom kris-bom commented Oct 8, 2026

Copy link
Copy Markdown

Fixes #1345

What does it do?

describe nanoflow now ends with the nanoflow's access rules, as describe microflow already does:

grant execute on nanoflow Shop.NF_Checkout to Shop.User, Shop.Admin;

Before this change the nanoflow describer left the grant out. Executing a nanoflow's description, or a
copy of it under a new name, gave a nanoflow no role could run.

Root cause: describeNanoflow (mdl/executor/cmd_microflows_show.go) is a separate copy of the flow
renderer. describeMicroflowMode and renderMicroflowMDL (the diff-local path) each had an inline grant
block, but describeNanoflow had none. The backend already fills Nanoflow.AllowedModuleRoles, and
show access on nanoflow lists the roles.

Change: the grant block is now one helper, grantExecuteLines(flowType, name, roles). All three
renderers call it, so they cannot drift apart on this line again. Microflow and diff-local output is
unchanged. A nanoflow without allowed roles still prints no grant.

Files

  • mdl/executor/cmd_microflows_show.go: adds grantExecuteLines, uses it in describeMicroflowMode,
    describeNanoflow and renderMicroflowMDL
  • mdl/executor/cmd_nanoflows_mock_test.go: two MockBackend tests
  • CHANGELOG.md: entry under Unreleased / Fixed
  • .claude/skills/fix-issue/findings/mdl-executor.jsonl: one finding

Testing

Tests were written first and failed on main (91ae198d):

--- FAIL: TestDescribeNanoflow_Mock_EmitsGrantExecute
    cmd_nanoflows_mock_test.go:140: output should contain "grant execute on nanoflow Shop.NF_Checkout to Shop.User, Shop.Admin;", got:
        create or modify nanoflow Shop.NF_Checkout ()
        begin
          -- No activities
        end;
  • TestDescribeNanoflow_Mock_EmitsGrantExecute: describes a nanoflow with roles Shop.User and
    Shop.Admin, checks the grant line, parses the whole output with visitor.Build, and asserts a
    GrantNanoflowAccessStmt for Shop.NF_Checkout with the same roles in the same order. This proves the
    round trip as well as the printed text.
  • TestDescribeNanoflow_Mock_NoRolesNoGrant: a nanoflow without roles prints no grant.
  • Fix proven to be the cause: I reverted only cmd_microflows_show.go and
    TestDescribeNanoflow_Mock_EmitsGrantExecute failed with the output above. With the fix restored it
    passes.
  • go test ./mdl/executor/ passes, go vet ./mdl/executor/ is clean, and gofmt -l mdl/executor/ is
    empty.
  • make check-findings passes.

End to end, with binaries built from main and from this branch on a Mendix 11.12.4 project: after create or modify nanoflow plus grant execute on nanoflow … to …, main's describe nanoflow ends at end;; this branch prints the grant execute on nanoflow line with both roles. The same main result reproduces on a copy of testdata/testapp-views (log in the issue).

Checklist

  • Issue filed first: describe nanoflow omits grant execute on nanoflow, so a describe -> exec round trip loses its access rules #1345
  • Fix-issue skill consulted. docs-wiki/bug-patterns/describe-round-trip-gaps.md covers this class.
    The closest finding (mdl/backend, 2026-06-30) was about the backend not reading the roles. That is
    fixed, so this is a new instance in the executor.
  • Finding recorded in .claude/skills/fix-issue/findings/mdl-executor.jsonl; make check-findings passes
  • Test written first and failed on main
  • Verified at the layer the symptom lives in: executor describe output, MockBackend, plus a parser round trip
  • Fix proven to be the cause (revert -> test fails -> restore -> test passes)
  • One commit, one concern
  • CHANGELOG entry
  • make test passes (full suite)
  • make lint-go, make check-conformance, make check-test-timeouts and make check-findings pass (Go 1.26.6, as pinned in go.mod); lint-ts not run locally (no bun here), and this PR touches no TypeScript
  • Mendix Studio Pro validation: not done for this PR. The change is read-only: it alters describe
    output only, and no BSON or write path changed. The emitted statement is the existing
    grant execute on nanoflow syntax.
  • Agentic testing: not done separately. Agents get the grant line through the normal
    describe nanoflow output.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

AI Code Review

Critical Issues

None found.

Moderate Issues

None found.

Minor Issues

None found.

What Looks Good

  • Root cause addressed: The PR correctly identifies that describeNanoflow was missing the grant execute block while microflow describers had it, causing nanoflows to lose access rules on round-trip.
  • Good refactor: Centralizing the grant block logic into grantExecuteLines prevents future duplication and ensures consistency across microflow, nanoflow, and diff-local paths.
  • Thorough testing:
    • Tests written first and failed on main (as required)
    • Verify both the text output and parser roundtrip (grant statement parsing)
    • Cover both cases: with roles (emits grant) and without roles (no grant)
    • Prove causation via revert/restore test
  • Process compliance:
  • Output correctness:
    • Uses existing grant execute on nanoflow syntax (no new MDL)
    • Maintains microflow/diff-local behavior unchanged
    • Properly formats role lists as comma-separated qualified names
    • Adds blank line before grant for readability (consistent with microflow output)

Recommendation

Approve. The PR fully addresses the issue with minimal, focused changes, proper testing, and adherence to project conventions. The read-only nature (no BSON/write changes) makes Studio Pro validation unnecessary as noted.


Automated review via OpenRouter (Nemotron Super 120B) — workflow source

describe nanoflow left out the nanoflow's allowed module roles, while
describe microflow ends with `grant execute on microflow ... to ...;`.
Executing a nanoflow's description therefore produced a nanoflow no role
could run.

describeNanoflow is a separate copy of the flow renderer and never had
the grant block that describeMicroflow and renderMicroflowMDL each
carried inline. Move that block into grantExecuteLines and use it in
all three, so the nanoflow describer prints
`grant execute on nanoflow M.NF to M.Role, ...;`.

The mock test parses the description back and asserts a
GrantNanoflowAccessStmt with the same roles; a nanoflow without roles
still prints no grant.

Co-Authored-By: Claude <noreply@anthropic.com>
@kris-bom
kris-bom force-pushed the fix/36-nanoflow-grants branch from bfca4e3 to f05eeb1 Compare October 8, 2026 22:46
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

AI Code Review

Critical Issues

None found.

Moderate Issues

None found.

Minor Issues

None found.

What Looks Good

  • The PR correctly addresses the issue: describe nanoflow now includes the grant execute line for access rules, matching the behavior of describe microflow.
  • The refactoring eliminates code duplication by introducing a shared grantExecuteLines helper function used by all three renderers (describe microflow, describe nanoflow, and render microflow MDL).
  • Tests are comprehensive: they verify both the positive case (roles present → grant line emitted) and negative case (no roles → no grant line), and include a round-trip parse check to ensure the output is valid MDL.
  • The fix is proven by reverting and restoring the change, confirming the test failure/resolution.
  • All project checks pass: make test, make lint-go, make check-conformance, make check-test-timeouts, and make check-findings.
  • The CHANGELOG entry is present and accurate.
  • The change follows the project's atomicity principle: one commit, one concern (fixing the missing grant line in nanoflow describe output).
  • No MDL syntax is modified; the change only affects the output of an existing command to include an existing statement (grant execute on nanoflow), so full-stack consistency is maintained via existing infrastructure.

Recommendation

Approve the PR. The change is correct, well-tested, and adheres to all project guidelines. No further action is needed.


Automated review via OpenRouter (Nemotron Super 120B) — workflow source

@ako

ako commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Implemented.

@ako ako closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

describe nanoflow omits grant execute on nanoflow, so a describe -> exec round trip loses its access rules

2 participants