fix(agent): strip TOML array-of-tables routes too #485

Merged
gmackie merged 1 commit from fix/route-entries-array-of-tables into main 2026-08-27 17:38:10 +00:00
Owner

Follow-up to #482, found by validating the shipped strip against real inputs instead of trusting synthetic fixtures.

The bug

stripManagedRoutes asserted cfg["routes"].([]any). TOML's array-of-tables form

[[routes]]
pattern = "driftport.io"
custom_domain = true

decodes to []map[string]any, so the assertion failed, the function returned early, and the strip was a silent no-op on every config using that syntax. driftport was left unprotected while the code reported success — the exact failure mode this feature exists to prevent, hiding inside the fix for it.

The inline form (routes = [{...}]) and plain string arrays both decode to []any, which is why every synthetic fixture passed.

How it surfaced

I fetched the actual wrangler config of all 22 enabled one-box apps and ran the strip over each. driftport reported "nothing stripped" while its config plainly declared the hostname. That harness is included (realcfg_validation_test.go), self-skipping unless FG_REALCFG_DIR is set, with a comment on how to build the corpus.

Result after the fix

  • 15 configs strip their managed hostname correctly
  • latchflow keeps lazer.latchflow.io while losing latchflow.io + www — selectivity proven on a real config
  • 6 strip nothing, each correctly: fabforge declares beta.fab.forgegraf.com while the split owns fab.forgegraf.com; playtrek and omnidat-app likewise declare beta/console subdomains; forgegraph's match is the explanatory comment #479 left behind
  • every rewritten config still parses as valid TOML/JSON, and no worker name was touched

Regression tests added for both real-world TOML shapes. Needs an agent release (0.1.62) to reach the fleet; until then array-of-tables apps stay covered by the reconcile.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f

Follow-up to #482, found by validating the shipped strip against real inputs instead of trusting synthetic fixtures. ## The bug `stripManagedRoutes` asserted `cfg["routes"].([]any)`. TOML's array-of-tables form ```toml [[routes]] pattern = "driftport.io" custom_domain = true ``` decodes to `[]map[string]any`, so the assertion failed, the function returned early, and **the strip was a silent no-op on every config using that syntax**. `driftport` was left unprotected while the code reported success — the exact failure mode this feature exists to prevent, hiding inside the fix for it. The inline form (`routes = [{...}]`) and plain string arrays both decode to `[]any`, which is why every synthetic fixture passed. ## How it surfaced I fetched the actual wrangler config of all 22 enabled one-box apps and ran the strip over each. `driftport` reported "nothing stripped" while its config plainly declared the hostname. That harness is included (`realcfg_validation_test.go`), self-skipping unless `FG_REALCFG_DIR` is set, with a comment on how to build the corpus. ## Result after the fix - 15 configs strip their managed hostname correctly - **latchflow keeps `lazer.latchflow.io`** while losing `latchflow.io` + `www` — selectivity proven on a real config - 6 strip nothing, each correctly: `fabforge` declares `beta.fab.forgegraf.com` while the split owns `fab.forgegraf.com`; `playtrek` and `omnidat-app` likewise declare beta/console subdomains; `forgegraph`'s match is the explanatory comment #479 left behind - every rewritten config still parses as valid TOML/JSON, and no worker `name` was touched Regression tests added for both real-world TOML shapes. Needs an agent release (0.1.62) to reach the fleet; until then array-of-tables apps stay covered by the reconcile. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f
fix(agent): strip TOML array-of-tables routes too
All checks were successful
CI / gitleaks (pull_request) Successful in 7s
CI / storybook (pull_request) Successful in 1m33s
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 9m39s
2f6b40a608
stripManagedRoutes asserted cfg["routes"].([]any), but TOML's
array-of-tables form

  [[routes]]
  pattern = "driftport.io"

decodes to []map[string]any. The assertion failed, the function returned
early, and the strip was a silent no-op on every config using that
syntax — driftport was left unprotected while reporting success.

Found by running the strip against the real wrangler config of all 22
enabled one-box apps rather than synthetic fixtures; that harness is
included here, self-skipping unless FG_REALCFG_DIR is set. Route entries
are now normalised, with regression tests for both real-world TOML
shapes (array-of-tables, and an inline table carrying zone_name).

Re-validated against the full corpus: 15 configs strip correctly,
latchflow keeps its unmanaged lazer.latchflow.io, and the 6 that strip
nothing each declare a different hostname than the split owns
(beta./console. subdomains).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!485
No description provided.