mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
* fix(integrations): validate and harden jira, jsm, ashby, google drive, slack, confluence, notion Audit and fix contract drift, input validation, and error handling across integrations: - Jira: NaN guards on worklog seconds, JSON.parse try/catch on internal API responses, domain normalization (strip leading https://), JQL injection prevention via project key validation, ADF helper consolidation, /search/jql nextPageToken pagination, defensive .trim() on ID path params, encodeURIComponent on watcher account IDs, resolveAssigneeAccountId helper, parent-as-object wrapping, summary fallback, add read-bulk operation. Restored total field (always null) to preserve contract. - JSM: customer/organization route validation - Ashby: types and tool output cleanup across all 30+ tools - Google Drive: tighter response handling across read/write/share tools - Slack: types and tool fixes (canvas, reactions, messaging, members) - Confluence: update tool and types - Docs: regenerated mdx for all touched integrations * fix(ashby): add subblock migrations for removed expand form definition fields * fix(slack): restore canvas_id fallback to data.id for backwards compat Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(jsm): explicit 400 when deprecated `emails` param is sent Address greptile review on PR #4345: instead of silently dropping `emails` and falling through to list-customers, return a 400 telling the caller to use `accountIds`. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(google_drive): include HTTP status in fallback error messages Address greptile review on PR #4345: when Google Drive returns a non-JSON error body, surface the response status/statusText so failures are diagnosable instead of falling through to a generic message. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ashby): drop stray websiteUrl→website remap for update_candidate The update_candidate tool reads params.websiteUrl directly; mapping it to result.website added a confusing dead field. The websiteUrl subBlock auto-passes through with the matching name. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(google_drive): rename canonical params to avoid subBlock ID clash `mimeType`, `query`, and `pageSize` canonical IDs collided with existing subBlock IDs in the same block (failing the canonical-param validation test). Drop the canonicalParamId from search/get_content single-input fields and route them to tool params explicitly in tools.config.params. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ashby): remove filterCandidateId from removed-subblock migrations The candidate-id filter was reintroduced as a valid Ashby subBlock, but the migration map still rewrote it to _removed_filterCandidateId on every workflow load, silently breaking the field. Drop the entry so user values persist. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ashby): restore documented response fields dropped during refactor Restore three fields that exist in Ashby's API responses but were dropped during the recent refactor: applicationLimitCalloutHtml on /jobPosting.info, compensation on /job.info (and add the `compensation` expand), and managerId on /user.list. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * correctness * updated types * fix(ashby): gate operation-specific param mappings to prevent stale overwrites Multiple subBlocks share the same target tool param (createdAt is set by appCreatedAt/candidateCreatedAt/noteCreatedAt; candidateId by appCandidateId/ filterCandidateId). Because subBlock values persist across operation switches, a stale value from a prior operation could silently overwrite the correct one. Guard each mapping with an explicit operation check. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ashby): gate offerApplicationId mapping by operation Same shared-target hazard as the prior fix: offerApplicationId maps to result.applicationId without an operation guard, so a stale value from list_offers could overwrite the active applicationId on get_application, change_application_stage, or list_interviews. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ashby): include list_locations in includeArchived condition Ashby's /location.list accepts includeArchived per the API docs, and the docs page already documents the toggle for list_locations. Add the missing operation value so the toggle renders. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(jira): forward explicit notifyUsers=true query param on issue update Block now distinguishes true/false/undefined for notifyUsers, but the route collapsed true and undefined into a no-param request. Forward the explicit true intent so it survives any future API default change or proxy override. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(jira): quote project key in JQL to defend against injection * fix(jira): quote project key in bulk_read JQL for defense in depth The alphanumeric regex check above already blocks injection, but quoting the project key matches the pattern used elsewhere (issues/route.ts) and hardens the path against future regex changes. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
docs
This is a Next.js application generated with Create Fumadocs.
Run development server:
bun run dev
Open http://localhost:3000 with your browser to see the result.
Learn More
To learn more about Next.js and Fumadocs, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
- Fumadocs - learn about Fumadocs
- Bun Documentation - learn about Bun features and API