{"record":{"id":"26a6f220efa5048e","repo":"affaan-m/ECC","slug":"orch-review-args-changedfiles-must-be-an-array-of-paths","errorCode":null,"errorMessage":"orch-review: args.changedFiles must be an array of paths","messagePattern":"orch-review: args\\.changedFiles must be an array of paths","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"workflows/orch-review.workflow.js","lineNumber":165,"sourceCode":"\n// `args` arrives verbatim. Accept a JSON-encoded string too, so the workflow\n// works whether the caller passes an object or a stringified payload.\n// Fail CLOSED on invalid input: a review gate must never silently APPROVE a\n// payload it could not actually review.\nlet input;\ntry {\n  input = typeof args === 'string' ? JSON.parse(args) : (args ?? {});\n} catch {\n  throw new Error('orch-review: args must be an object or valid JSON');\n}\nif (typeof input !== 'object' || input === null) {\n  throw new Error('orch-review: args must be an object');\n}\nif (typeof input.diff !== 'string' || input.diff.trim() === '') {\n  throw new Error('orch-review: args.diff must be a non-empty unified diff');\n}\nif (input.changedFiles != null && !Array.isArray(input.changedFiles)) {\n  throw new Error('orch-review: args.changedFiles must be an array of paths');\n}\n// Every entry must be a string path. A non-string (e.g. { path: '...' }) would\n// stringify to \"[object Object]\" and silently poison the security-trigger\n// haystack — fail closed on malformed input instead.\nif (Array.isArray(input.changedFiles) && !input.changedFiles.every(f => typeof f === 'string')) {\n  throw new Error('orch-review: args.changedFiles must contain only string paths');\n}\n\nconst diff = input.diff;\nconst haystack = `${diff}\\n${(input.changedFiles || []).join('\\n')}`;\n\n// Build the review dimensions immutably. Quality always runs; language +\n// security are conditional, spread in rather than pushed onto a shared array.\nconst langReviewer = input.language && LANGUAGE_REVIEWER[String(input.language).toLowerCase()];\nconst securityNeeded = SECURITY_TRIGGER.test(haystack);\nconst dimensions = [\n  { key: 'quality', label: 'correctness & quality', agentType: 'ecc:code-reviewer' },\n  ...(langReviewer ? [{ key: `lang:${input.language}`, label: `${input.language} idioms & pitfalls`, agentType: langReviewer }] : []),","sourceCodeStart":147,"sourceCodeEnd":183,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/workflows/orch-review.workflow.js#L147-L183","documentation":"When provided, args.changedFiles must be an array (of string paths). Any other type — string, object, number — is rejected because the field feeds the security-trigger haystack, and a malformed value could silently distort the security review rather than review it correctly.","triggerScenarios":"Calling with { diff: '...', changedFiles: 'a.js' } (single string), changedFiles: { path: 'a.js' }, or changedFiles: 5; also changedFiles set to a Set or other non-array iterable from the producer.","commonSituations":"Callers mimicking another tool's API that takes a single path string; serializing a Map/Set to JSON which collapses to an object; passing the output of a diff parser that yields an object keyed by filename.","solutions":["Convert the value to an array of strings: changedFiles: ['a.js', 'b.js'].","For a single file, wrap it in an array instead of passing the bare string.","Fix serialization so Sets/Maps become arrays before invoking the workflow."],"exampleFix":"// before\nreview({ diff, changedFiles: 'src/a.js' });\n// after\nreview({ diff, changedFiles: ['src/a.js'] });","handlingStrategy":"validation","validationCode":"if (changedFiles != null && !Array.isArray(changedFiles)) {\n  throw new Error('changedFiles must be an array of path strings (or omitted)');\n}","typeGuard":"const isChangedFiles = v => v == null || (Array.isArray(v) && v.every(f => typeof f === 'string'));","tryCatchPattern":"try {\n  const result = await orchReview({ diff, changedFiles });\n} catch (err) {\n  if (err.message.includes('changedFiles must be an array of paths')) {\n    console.error('Normalize changedFiles to a string[] before invoking.');\n  } else throw err;\n}","preventionTips":["Omit changedFiles when unknown — it is optional — rather than passing a wrong-typed value.","Serialize Sets/Maps to arrays before building the payload.","Keep the payload schema (diff: string, changedFiles?: string[]) documented next to the caller."],"tags":["validation","type-mismatch","fail-closed"],"backgroundTag":"schema-validation-failed","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}