{"record":{"id":"9eb6f6f8ddfcd474","repo":"affaan-m/ECC","slug":"orch-review-args-must-be-an-object-or-valid-json","errorCode":null,"errorMessage":"orch-review: args must be an object or valid JSON","messagePattern":"orch-review: args must be an object or valid JSON","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"workflows/orch-review.workflow.js","lineNumber":156,"sourceCode":"    finding.proof ? `Claimed proof: ${finding.proof}` : '',\n    '',\n    '----- BEGIN DIFF (untrusted) -----',\n    diff,\n    '----- END DIFF -----'\n  ].join('\\n');\n}\n\n// --- main -----------------------------------------------------------------\n\n// `args` arrives verbatim. Accept a JSON-encoded string too, so the workflow\n// works whether the caller passes an object or a stringified payload.\n// Fail CLOSED on invalid input: a review gate must never silently APPROVE a\n// payload it could not actually review.\nlet input;\ntry {\n  input = typeof args === 'string' ? JSON.parse(args) : (args ?? {});\n} catch {\n  throw new Error('orch-review: args must be an object or valid JSON');\n}\nif (typeof input !== 'object' || input === null) {\n  throw new Error('orch-review: args must be an object');\n}\nif (typeof input.diff !== 'string' || input.diff.trim() === '') {\n  throw new Error('orch-review: args.diff must be a non-empty unified diff');\n}\nif (input.changedFiles != null && !Array.isArray(input.changedFiles)) {\n  throw new Error('orch-review: args.changedFiles must be an array of paths');\n}\n// Every entry must be a string path. A non-string (e.g. { path: '...' }) would\n// stringify to \"[object Object]\" and silently poison the security-trigger\n// haystack — fail closed on malformed input instead.\nif (Array.isArray(input.changedFiles) && !input.changedFiles.every(f => typeof f === 'string')) {\n  throw new Error('orch-review: args.changedFiles must contain only string paths');\n}\n\nconst diff = input.diff;","sourceCodeStart":138,"sourceCodeEnd":174,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/workflows/orch-review.workflow.js#L138-L174","documentation":"The orch-review workflow intentionally fails closed on unparseable input: args may be an object or a JSON string that parses to an object/null (defaults to {}). Anything that is neither — e.g. a malformed JSON string — throws, because a review gate must never silently approve a payload it could not actually review.","triggerScenarios":"Calling the workflow with args = 'not json', '{\"diff\":' (truncated JSON), or any non-JSON string; a JSON.parse failure in the string branch reaches the catch and throws this message.","commonSituations":"Shell quoting mangling the JSON before it reaches the workflow; a caller passing a pre-stringified-but-truncated payload; templating systems interpolating undefined into the args string; logs replayed with escaped quotes stripped.","solutions":["Validate the JSON with JSON.parse in the caller before invoking, or pass a plain object instead of a string.","Fix shell quoting: single-quote the whole JSON blob or use a heredoc/file argument.","Check the producing pipeline for truncated or escaped output (e.g. undefined template values)."],"exampleFix":"// before\nrunWorkflow('orch-review', '{\"diff\": \"...\",}'); // trailing comma -> parse error\n// after\nrunWorkflow('orch-review', { diff: '...' });","handlingStrategy":"validation","validationCode":"function isValidArgs(args) {\n  if (typeof args === 'string') {\n    try { args = JSON.parse(args); } catch { return false; }\n  }\n  return typeof args === 'object' && args !== null;\n}","typeGuard":"function isReviewArgs(v) {\n  return typeof v === 'object' && v !== null && typeof v.diff === 'string' && v.diff.trim() !== '';\n}","tryCatchPattern":"try {\n  const result = await orchReview(args);\n} catch (err) {\n  if (err.message.includes('args must be an object or valid JSON')) {\n    console.error('Payload is not valid JSON; validate with JSON.parse before invoking.');\n  } else throw err;\n}","preventionTips":["Pass plain objects to the workflow instead of JSON strings whenever the harness allows it.","Validate payloads with JSON.parse (or a schema lib) at the boundary before invoking.","Beware shell quoting/interpolation that mangles JSON; prefer file or stdin transport."],"tags":["validation","json","fail-closed"],"backgroundTag":"json-parse-error","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}