Go to file
Lucio Lelii 6ed8fc748f feat: validate placeholder-derived input names on LLM/HumanInteraction/HumanDecision
Nothing today rejects a ${{...}} placeholder whose captured name contains
spaces, symbols, or brackets: the capture group is `.*?`, so it accepts
anything between ${{ and }}. That name flows straight into an IODescriptor
with no further checks.

Adds an @AssertTrue check (same convention as the existing
isOptionsUnique()/areSkillIdsUnique() checks) on LLMBlockConfiguration.prompt,
HumanInteractiveBlockConfiguration.actionDescription and
HumanDecisionBlockConfiguration.question, requiring every placeholder name to
start with a letter and contain only letters, digits, '-', '_' or '.'.

'.' stays allowed because it's already load-bearing: LoopContainer guard
prompts reference inputs.<name>/outputs.<name>
(ExecutionsService.buildGuardTemplateValues), and colliding container-exposed
names get qualified as nodeName.ioName
(ContainerFlowInterfaceResolver.qualifyWithNodeName). Confirmed via the full
suite - the first pass of this change broke 5 Loop container tests before
'.' was added back.

'[' and ']' stay rejected on purpose, reserving that syntax for a possible
future array-input marker on placeholder names.

TemplateInputs made public (was package-private) so the three
BlockConfiguration classes, which live in a different package, can call the
new hasValidPlaceholderNames() check.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 09:55:24 +02:00
.mvn/wrapper upgrade to springboot 4 2026-05-05 19:22:53 +02:00
src feat: validate placeholder-derived input names on LLM/HumanInteraction/HumanDecision 2026-07-24 09:55:24 +02:00
.gitattributes first commit 2025-03-27 11:38:06 +01:00
.gitignore Improve assistant model routing and diagnostics 2026-05-20 12:27:09 +02:00
Dockerfile Update Dockerfile for Java 25 2026-04-17 14:11:02 +02:00
mvnw first commit 2025-03-27 11:38:06 +01:00
mvnw.cmd first commit 2025-03-27 11:38:06 +01:00
ollama-preloaded-docker image for test with ollama added 2025-09-29 17:00:57 +02:00
pom.xml fix: add missing Flyway autoconfiguration and shorten an overlong flow description 2026-07-22 15:24:51 +02:00