Skip to content

fix: escape workflow step metadata - #3863

Merged
mnriem merged 1 commit into
github:mainfrom
marcelsafin:fix/step-rich-output
Jul 30, 2026
Merged

fix: escape workflow step metadata#3863
mnriem merged 1 commit into
github:mainfrom
marcelsafin:fix/step-rich-output

Conversation

@marcelsafin

Copy link
Copy Markdown
Contributor

Summary

  • render installed and catalog step metadata literally in list, search, and info output
  • escape echoed step IDs, including the not-found path
  • preserve intentional Rich formatting around untrusted values

Testing

  • uvx ruff@0.15.0 check src tests
  • .venv/bin/python -m pytest -q tests/test_workflows.py (822 passed)
  • .venv/bin/python -m pytest -q (6012 passed, 173 skipped)

AI disclosure

GitHub Copilot helped identify affected output paths and review the implementation. I reproduced the failures and validated the final change with targeted and full test suites.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@marcelsafin
marcelsafin requested a review from mnriem as a code owner July 29, 2026 18:05
Copilot AI review requested due to automatic review settings July 29, 2026 18:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Escapes untrusted workflow step metadata while preserving intentional Rich formatting.

Changes:

  • Escapes metadata in step list, search, and info output.
  • Adds regression tests for catalog, installed, and missing-step output.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/specify_cli/workflows/_commands.py Escapes step metadata and IDs before rendering.
tests/test_workflows.py Tests literal Rich markup rendering.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Ready to approve

The escaping is consistently applied and covered by focused regression tests.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Medium

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

@mnriem
mnriem merged commit 0f3f2aa into github:main Jul 30, 2026
14 checks passed
@mnriem

mnriem commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants