Repository navigation
Conversation
AI Code ReviewCritical IssuesNone found. Moderate IssuesNone found. Minor IssuesNone found. What Looks Good
RecommendationApprove. The PR fully addresses the issue with minimal, focused changes, proper testing, and adherence to project conventions. The read-only nature (no BSON/write changes) makes Studio Pro validation unnecessary as noted. Automated review via OpenRouter (Nemotron Super 120B) — workflow source |
describe nanoflow left out the nanoflow's allowed module roles, while describe microflow ends with `grant execute on microflow ... to ...;`. Executing a nanoflow's description therefore produced a nanoflow no role could run. describeNanoflow is a separate copy of the flow renderer and never had the grant block that describeMicroflow and renderMicroflowMDL each carried inline. Move that block into grantExecuteLines and use it in all three, so the nanoflow describer prints `grant execute on nanoflow M.NF to M.Role, ...;`. The mock test parses the description back and asserts a GrantNanoflowAccessStmt with the same roles; a nanoflow without roles still prints no grant. Co-Authored-By: Claude <noreply@anthropic.com>
kris-bom
force-pushed
the
fix/36-nanoflow-grants
branch
from
October 8, 2026 22:46
bfca4e3 to
f05eeb1
Compare
AI Code ReviewCritical IssuesNone found. Moderate IssuesNone found. Minor IssuesNone found. What Looks Good
RecommendationApprove the PR. The change is correct, well-tested, and adheres to all project guidelines. No further action is needed. Automated review via OpenRouter (Nemotron Super 120B) — workflow source |
Collaborator
|
Implemented. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1345
What does it do?
describe nanoflownow ends with the nanoflow's access rules, asdescribe microflowalready does:Before this change the nanoflow describer left the grant out. Executing a nanoflow's description, or a
copy of it under a new name, gave a nanoflow no role could run.
Root cause:
describeNanoflow(mdl/executor/cmd_microflows_show.go) is a separate copy of the flowrenderer.
describeMicroflowModeandrenderMicroflowMDL(thediff-localpath) each had an inline grantblock, but
describeNanoflowhad none. The backend already fillsNanoflow.AllowedModuleRoles, andshow access on nanoflowlists the roles.Change: the grant block is now one helper,
grantExecuteLines(flowType, name, roles). All threerenderers call it, so they cannot drift apart on this line again. Microflow and
diff-localoutput isunchanged. A nanoflow without allowed roles still prints no grant.
Files
mdl/executor/cmd_microflows_show.go: addsgrantExecuteLines, uses it indescribeMicroflowMode,describeNanoflowandrenderMicroflowMDLmdl/executor/cmd_nanoflows_mock_test.go: two MockBackend testsCHANGELOG.md: entry under Unreleased / Fixed.claude/skills/fix-issue/findings/mdl-executor.jsonl: one findingTesting
Tests were written first and failed on
main(91ae198d):TestDescribeNanoflow_Mock_EmitsGrantExecute: describes a nanoflow with rolesShop.UserandShop.Admin, checks the grant line, parses the whole output withvisitor.Build, and asserts aGrantNanoflowAccessStmtforShop.NF_Checkoutwith the same roles in the same order. This proves theround trip as well as the printed text.
TestDescribeNanoflow_Mock_NoRolesNoGrant: a nanoflow without roles prints no grant.cmd_microflows_show.goandTestDescribeNanoflow_Mock_EmitsGrantExecutefailed with the output above. With the fix restored itpasses.
go test ./mdl/executor/passes,go vet ./mdl/executor/is clean, andgofmt -l mdl/executor/isempty.
make check-findingspasses.End to end, with binaries built from main and from this branch on a Mendix 11.12.4 project: after
create or modify nanoflowplusgrant execute on nanoflow … to …, main'sdescribe nanoflowends atend;; this branch prints thegrant execute on nanoflowline with both roles. The same main result reproduces on a copy oftestdata/testapp-views(log in the issue).Checklist
docs-wiki/bug-patterns/describe-round-trip-gaps.mdcovers this class.The closest finding (mdl/backend, 2026-06-30) was about the backend not reading the roles. That is
fixed, so this is a new instance in the executor.
.claude/skills/fix-issue/findings/mdl-executor.jsonl;make check-findingspassesmainmake testpasses (full suite)make lint-go,make check-conformance,make check-test-timeoutsandmake check-findingspass (Go 1.26.6, as pinned ingo.mod);lint-tsnot run locally (no bun here), and this PR touches no TypeScriptoutput only, and no BSON or write path changed. The emitted statement is the existing
grant execute on nanoflowsyntax.describe nanoflowoutput.🤖 Generated with Claude Code