Commit Graph

922 Commits

Author SHA1 Message Date
Peter Wielander 24a041fa14 Remove remaining changeset files for clean GA release (#1638) workflow@4.2.0-beta.77 2026-04-07 12:01:07 -07:00
Peter Wielander 71599cfbe6 Remove old changeset files to fix release timeout (#1636) 2026-04-07 11:50:17 -07:00
Peter Wielander 10413755a2 Clear consumed changesets from pre.json to fix release timeout (#1623) 2026-04-07 11:27:07 -07:00
Peter Wielander f0d6a85ddd [cli] [core] Probe deployment specVersion before CLI start (#1629) 2026-04-07 11:18:42 -07:00
Peter Wielander e8527e02ec [core] Propagate stream cancellation to avoid leaking listeners (#1618) 2026-04-07 11:18:42 -07:00
Peter Wielander 06c265c416 [ai] Fixes DurableAgent telemetry missing AI SDK-compatible span attributes (#1608) 2026-04-07 11:18:42 -07:00
John Lindquist 5b6d0779c0 docs: March docs audit and alignment (#1466)
* docs: clarify Next monorepo setup

Prevent confusion when Next.js apps live below the repository root and workflow code imports sibling workspace packages.

This documents the output tracing root requirement at the point where users configure withWorkflow, so monorepo setups follow the same working patterns as the shipped Next.js integration instead of failing due to unresolved workspace imports.

Ploop-Iter: 1

* ploop: iteration 2 checkpoint

Automated checkpoint commit.

Ploop-Iter: 2

* ploop: iteration 3 checkpoint

Automated checkpoint commit.

Ploop-Iter: 3

* docs: audit recent documentation coverage

Capture recent workflow documentation updates so the public docs and package guidance stay aligned with the implementation and current docs-typecheck behavior.

Ploop-Iter: 1

* docs: align docs-typecheck docs

Document the current docs verification contract so contributors do not assume JavaScript examples are type-checked when only TypeScript snippets are enforced today.

Add regression coverage around the README language and framework integration guidance to keep those docs aligned with the implemented Next.js and docs-typecheck behavior as future changes land.

Ploop-Iter: 2

* docs: add start() troubleshooting guidance

Document the most common causes of the invalid workflow function error so users can resolve start() failures from the API docs and Next.js setup flow without having to infer build-time requirements from runtime behavior.

Keep the new troubleshooting page aligned with the shipped runtime message and add regression coverage so future wording or cross-link changes do not silently break that guidance.

Ploop-Iter: 3

* docs: align NestJS setup docs

Document both supported NestJS module formats and add a regression check so the getting-started guide stays aligned with the package README as the integration evolves.

Ploop-Iter: 1

* docs: tighten NestJS CommonJS guidance

Keep the NestJS getting-started guide consistent across the ESM and CommonJS paths so readers do not mix module settings or import styles mid-setup.

Strengthen the docs regression coverage around the later guide sections so future edits are more likely to preserve the supported CommonJS path documented in the package README.

Ploop-Iter: 2

* docs: align docs with recent workflow guidance

Document the recently added troubleshooting and observability patterns so the public docs stay aligned with the behavior users now encounter in practice.

This keeps the NestJS guide, workflow API reference, and docs regression coverage in sync with the runtime-facing guidance from recent changes.

Ploop-Iter: 3

* docs: audit docs coverage

Why: keep the docs aligned with recent API and runtime behavior changes so examples and reference pages don’t drift from the supported surface.

Ploop-Iter: 1

* test: add docs audit guards

Add regression coverage for doc surfaces that are easy to drift from implementation so docs audits catch mismatches early and keep published guidance aligned with the supported API surface.

Ploop-Iter: 2

* docs: add docs audit guards

Keep new observability and server-testing guidance anchored to machine-readable interfaces so follow-up implementation changes do not silently drift away from the documented agent and automation patterns.

Ploop-Iter: 3

* docs: align observability troubleshooting guidance

Keep the docs consistent so users get the same guidance when debugging hook token collisions and correlating workflow events with platform logs.

This prevents the event-sourcing reference from drifting away from the observability and error docs, and adds guard tests to catch regressions.

Ploop-Iter: 1

* Remove the unreferenced image file img-a-clean-minimal-technical-architecture-d-2026-02-27T14-07-52-1.png from the repo root, workbench/fastify/public/index.html (a Nitro example mistakenly placed in the fastify workbench by a ploop checkpoint), all .claude/worktrees/* submodule references, and all 15 string-presence audit guard tests in packages/docs-typecheck/src/__tests__/ (they only assert keyword presence, not semantic correctness). None of these belong in the docs audit PR.

* Address all PR #1466 review feedback from VaguelySerious, pranaygp, and ijjk:

1. Remove the "Machine-Readable Surfaces" section from docs/content/docs/observability/index.mdx (reviewers say it's unnecessary and already in world docs)
2. Remove all @skip-typecheck annotations from durable-agent.mdx (8) and server-based.mdx (1) — types exist in built packages/ai/dist after pnpm build
3. In durable-agent.mdx, change "machine-readable tool activity" to "tool call details" in the stream() return description
4. In durable-agent.mdx "Aborting Long-Running Streams" section, add a warning callout that abortSignal is not yet supported (blocked by #1301), recommend timeout instead
5. In event-sourcing.mdx, update requestId description: "On Vercel, requestId is the platform request ID when available. Other worlds are not expected to provide a requestId."
6. In get-world.mdx, change "user-friendly names from the machine-readable workflowName field" to "human-readable names from the workflowName field"
7. In start-invalid-workflow-function.mdx, add "// Does NOT work" comment above the bad example line
8. In with-workflow.mdx: reframe outputFileTracingRoot as a workaround (Next.js auto-detects by default per ijjk); change options description from "control local development behavior" to "configure the Next.js integration"; scope the callout to "workflows.local options only affect local development"
9. Drop the withWorkflow() options callout from docs/content/docs/getting-started/next.mdx
10. Remove the Next.js-specific outputFileTracingRoot callout from framework-integrations.mdx
11. Add a Troubleshooting section with the start() invalid-workflow-function error to all 9 non-Next getting-started guides (astro, express, fastify, hono, nestjs, nitro, nuxt, sveltekit, vite), each with framework-appropriate config check in point 2

* docs: absorb unique accuracy fixes from PR #1200

Cherry-picked 6 still-needed fixes from #1200 that aren't covered by
this audit PR or #1516:
- Fix npx workflow description (observability)
- Remove fetch from restricted modules list (errors)
- Fix package name @workflow-worlds/postgres → @workflow/world-postgres (deploying)
- Fix stream wording (foundations/starting-workflows)
- Fix import path simple → simple-streaming (foundations/streaming)
- Add close(), getEncryptionKeyForRun(), writeToStreamMulti() to World interface,
  update create() and streamer signatures (deploying/building-a-world)

* docs: address review feedback on March docs audit

- durable-agent.mdx: "structured tool activity" → "tool call information"
  per VaguelySerious's suggestion
- next.mdx: drop monorepo callout from getting-started per pranaygp
  (too much context too early; info is in withWorkflow API ref)

* docs: fix 2 typecheck failures in encryption and nestjs guides

- encryption.mdx: add skip-typecheck for interface signature block
  (getEncryptionKeyForRun overloads are not runnable code)
- nestjs.mdx: add skip-typecheck for WorkflowModule.forRoot config
  snippet (fragment inside callout, full import shown above)

Verified: pnpm vitest run passes 300/300 in docs-typecheck.
2026-04-07 11:18:42 -07:00
John Lindquist 35a288485b fix(next): remove unused dataDir option from withWorkflow() (#1619)
The `dataDir` option was accepted in the type definition but never
read — `WORKFLOW_LOCAL_DATA_DIR` was unconditionally set to
`.next/workflow-data`. Remove the dead option to avoid confusion.
2026-04-07 11:18:42 -07:00
Peter Wielander c81bbc9564 [core] [world] Gate CBOR queue transport on specVersion (#1627) 2026-04-07 11:18:42 -07:00
Matan Kushner b193447fe1 [builders] Resolve path aliases when externalizing non-step imports (#1613) 2026-04-07 11:18:42 -07:00
Peter Wielander b2914ab143 [world-vercel] Paginate writeToStreamMulti (#1626) 2026-04-07 11:18:42 -07:00
Peter Wielander deef87a40f chore: trigger release workflow
Signed-off-by: Peter Wielander <mittgfu@gmail.com>
2026-04-06 14:22:17 -07:00
Pranay Prakash 125c38708e [changeset] Exit pre-release mode (to release 4.2 stable) (#1508) 2026-04-06 13:52:46 -07:00
Peter Wielander d631152a65 Support dual-branch releases (stable + main) (#1620)
- Add `stable` to release workflow trigger branches
- Make npm dist-tag conditional: `stable` gets `latest`, `main` keeps `beta` (from changeset publish)
- Make GitHub release flags branch-aware: stable = latest + non-prerelease, main = prerelease + not latest
- Change changeset baseBranch to `stable` for this branch
2026-04-06 13:51:53 -07:00
Peter Wielander 7e70d1823a [core] Add configurable stream flush interval per world (#1533) 2026-04-06 12:38:01 -07:00
Peter Wielander c8dce52606 [core] [world] Lazy run creation on start (#1537) 2026-04-06 12:25:23 -07:00
Nathan Rajlich 9d195308c2 fix(ci): use Node 24 for releases and remove npm self-update (#1614) 2026-04-06 09:43:03 -07:00
Nathan Rajlich 2680a427f0 fix: add Request and Response revivers to web and CLI hydration (#1414) 2026-04-06 06:30:36 +00:00
Nathan Rajlich ba916e1566 Add DOMException to VM context and first-class serialization support (#1512)
- Pass DOMException through to the workflow VM context alongside other
  Web APIs (Headers, URL, TextEncoder, etc.)
- Add DOMException reducer/reviver to the serialization pipeline,
  preserving message, name, derived code, and cause when present
- Add DOMException to the Serializable type union
- 8 new tests: round-trip for AbortError, NotFoundError, default name,
  cause preservation, cause absence, serialization key, cross-VM
  boundaries, and VM context availability
2026-04-06 06:10:30 +00:00
workflow-devkit-release-bot[bot] 29fe9ded57 Version Packages (beta) (#1600) 2026-04-03 17:05:54 -07:00
Peter Wielander ab872cc9fb [core] Make registeredSteps a global singleton to protect against module duplication (#1606) 2026-04-03 21:53:58 +00:00
Gregor Martynus e9ebe8faa3 [ai] Preserve reasoning content in DurableAgent conversation history (#1444)
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
2026-04-03 14:42:10 -07:00
Nathan Rajlich f5d2aef58f Add serde compliance tooling and improve custom class serialization DX (#1552)
* Add serde compliance tooling and update skill documentation

- Add serde compliance checker library to @workflow/builders
- Add build-time warnings for serde classes with Node.js imports in workflow bundle
- Add 'workflow transform' CLI command for inspecting SWC output
- Implement 'workflow validate' CLI command with serde compliance checks
- Add serde analysis panel to SWC playground
- Update workflow skill with custom class serialization documentation

* Fix --json + --strict: use process.exitCode so JSON output is returned before exit

* Address code review feedback

- Fix --strict exit code: honor process.exitCode in BaseCommand.finally()
- Remove unused --module-specifier flag from transform command
- Add missing Node.js builtins (e.g. test) to playground detection list
- De-dupe build-time serde warnings by grouping identical issues across classes
- Make Serde Analysis panel collapsible like the output panels

* Use .gitignore for validate file discovery; fix changeset wording
2026-04-03 21:03:59 +00:00
Peter Wielander d8aaf27c79 [core] Enforce single ALS context to protect against duplicate module and caching issues (#1591) 2026-04-03 13:47:19 -07:00
Nathan Rajlich 7c996a76c5 fix(swc-plugin): rewrite anonymous export default class to const declaration (#1601)
* fix(builders): override sideEffects:false for discovered workflow/step/serde entries

When node_modules packages include "sideEffects": false in their
package.json, esbuild drops bare imports from the virtual-entry.js
file. This is incorrect because the SWC compiler transform injects
side-effectful registration code (workflow IDs, step IDs, class
serialization) into these modules.

Fix: return the resolved path alongside sideEffects: true from the
onResolve handler so esbuild uses the plugin's resolution result
instead of re-reading the package.json.

* refactor(builders): normalize sideEffectEntries with realpaths for symlink compatibility

Extract withRealpaths() helper and use it for both normalizedEntriesToBundle
and sideEffectEntries at all three bundle sites. This ensures the
sideEffects override works correctly under pnpm/workspace symlinked
layouts where enhanced-resolve may return realpaths that differ from
the original discovered file paths.

* perf(builders): skip enhanced-resolve for transitive imports when only sideEffectEntries is set

When entriesToBundle is not set (workflow/client bundles), only top-level
import statements need the sideEffects override — transitive imports
from deep within the bundle are not bare imports and don't need resolution.
Skip enhanced-resolve for non-import-statement kinds to reduce overhead.

* fix(swc-plugin): use binding name for class expression method registrations

When a pre-bundled package (e.g. via tsup) contains class expressions
like `var Foo = class _Foo { ... }`, the internal name `_Foo` is only
scoped inside the class body. The SWC plugin was incorrectly using the
internal name for method step registrations and class serialization
registrations emitted at module scope, causing ReferenceError at runtime.

Fix: always use the binding name (registration_name) for
current_class_name in visit_mut_class_expr, consistent with the existing
handling for anonymous class expressions. This ensures:
- registerStepFunction calls reference the binding name (Foo)
- Only one class registration IIFE is emitted (not duplicates for both
  Foo and _Foo)
- Step IDs use the binding name in their qualified path

* refactor(swc-plugin): rename internal_class_name to tracked_class_name for clarity

The variable no longer represents the internal class expression identifier
after being reassigned to the binding name. Rename to tracked_class_name
and eliminate the intermediate registration_name variable to make the
intent clearer and reduce confusion for future readers.

* fix(swc-plugin): rewrite anonymous export default class to const declaration

When an anonymous class with serde/step methods is exported as a default
export (`export default class { ... }`), the generated registration code
(registerStepFunction, class registry IIFE) would reference a nonexistent
variable at module scope, causing a ReferenceError at runtime.

Fix: detect anonymous default class exports in visit_mut_export_default_decl
and visit_mut_export_default_expr, generate a unique binding name
(__defaultClass), and defer a rewrite in visit_mut_module_items that
transforms the export into:
  const __defaultClass = class __defaultClass { ... };
  export default __defaultClass;

Named default class exports (export default class Foo { ... }) are
handled by setting current_class_binding_name so the transformer
uses the existing class name for registration code.

* refactor(swc-plugin): rename __defaultClass to __DefaultClass for class naming convention

* fix(swc-plugin): fix panic for step-only anonymous default class exports

Address review feedback:
- Remove expect() that panicked when anonymous default class had step
  methods but no serde methods (ident was not re-inserted). Keep
  const_name in a local variable instead of relying on class_expr.ident.
- Add debug_assert for single default class export invariant.
- Update spec.md and test fixture inputs to use new this() instead of
  referencing the generated binding name.
- Add step-only anonymous default class fixture to cover the bug path.

* refactor(swc-plugin): address review feedback for export default class handling

- Remove dead Expr::Class handler in visit_mut_export_default_expr
  (SWC wraps parenthesized form in Expr::Paren, so it never fires)
- Extract class_needs_binding_rewrite() helper, eliminating duplicated
  detection logic and unnecessary body clones
- Add debug_assert for mutual exclusivity of default_workflow_exports
  and default_class_exports
- Clarify spec.md on self-name behavior difference between serde and
  step-only classes
2026-04-03 19:54:20 +00:00
Peter Wielander b30b0dcab6 [world] Asymmetric ULID timestamp validation thresholds (#1605) 2026-04-03 12:54:09 -07:00
Pranay Prakash d1330cfebc Fix node-module-error plugin matching identifiers in multi-line comments (#1554)
* Fix node-module-error plugin matching identifiers in multi-line comments

The findIdentifierUsage function only stripped single-line comments and
same-line block comments, but didn't track multi-line block comment state.
Lines inside JSDoc/block comments (e.g. ` * ... Writable stream`) passed
through unstripped, causing the plugin to point at comments instead of
actual code usage.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Strip string literals before scanning for comment delimiters

Move string stripping before comment detection so that comment delimiters
inside string literals (e.g. `const s = "/*"`) don't incorrectly trigger
block comment mode. Adds regression test.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
2026-04-03 11:55:11 -07:00
Nathan Rajlich 5d22e61446 fix(swc-plugin): use binding name for class expression method registrations (#1599)
* fix(builders): override sideEffects:false for discovered workflow/step/serde entries

When node_modules packages include "sideEffects": false in their
package.json, esbuild drops bare imports from the virtual-entry.js
file. This is incorrect because the SWC compiler transform injects
side-effectful registration code (workflow IDs, step IDs, class
serialization) into these modules.

Fix: return the resolved path alongside sideEffects: true from the
onResolve handler so esbuild uses the plugin's resolution result
instead of re-reading the package.json.

* refactor(builders): normalize sideEffectEntries with realpaths for symlink compatibility

Extract withRealpaths() helper and use it for both normalizedEntriesToBundle
and sideEffectEntries at all three bundle sites. This ensures the
sideEffects override works correctly under pnpm/workspace symlinked
layouts where enhanced-resolve may return realpaths that differ from
the original discovered file paths.

* perf(builders): skip enhanced-resolve for transitive imports when only sideEffectEntries is set

When entriesToBundle is not set (workflow/client bundles), only top-level
import statements need the sideEffects override — transitive imports
from deep within the bundle are not bare imports and don't need resolution.
Skip enhanced-resolve for non-import-statement kinds to reduce overhead.

* fix(swc-plugin): use binding name for class expression method registrations

When a pre-bundled package (e.g. via tsup) contains class expressions
like `var Foo = class _Foo { ... }`, the internal name `_Foo` is only
scoped inside the class body. The SWC plugin was incorrectly using the
internal name for method step registrations and class serialization
registrations emitted at module scope, causing ReferenceError at runtime.

Fix: always use the binding name (registration_name) for
current_class_name in visit_mut_class_expr, consistent with the existing
handling for anonymous class expressions. This ensures:
- registerStepFunction calls reference the binding name (Foo)
- Only one class registration IIFE is emitted (not duplicates for both
  Foo and _Foo)
- Step IDs use the binding name in their qualified path

* refactor(swc-plugin): rename internal_class_name to tracked_class_name for clarity

The variable no longer represents the internal class expression identifier
after being reassigned to the binding name. Rename to tracked_class_name
and eliminate the intermediate registration_name variable to make the
intent clearer and reduce confusion for future readers.
2026-04-03 18:36:27 +00:00
Nathan Rajlich 443a9e62f9 fix(builders): override sideEffects: false for discovered workflow/step/serde entries (#1598)
* fix(builders): override sideEffects:false for discovered workflow/step/serde entries

When node_modules packages include "sideEffects": false in their
package.json, esbuild drops bare imports from the virtual-entry.js
file. This is incorrect because the SWC compiler transform injects
side-effectful registration code (workflow IDs, step IDs, class
serialization) into these modules.

Fix: return the resolved path alongside sideEffects: true from the
onResolve handler so esbuild uses the plugin's resolution result
instead of re-reading the package.json.

* refactor(builders): normalize sideEffectEntries with realpaths for symlink compatibility

Extract withRealpaths() helper and use it for both normalizedEntriesToBundle
and sideEffectEntries at all three bundle sites. This ensures the
sideEffects override works correctly under pnpm/workspace symlinked
layouts where enhanced-resolve may return realpaths that differ from
the original discovered file paths.

* perf(builders): skip enhanced-resolve for transitive imports when only sideEffectEntries is set

When entriesToBundle is not set (workflow/client bundles), only top-level
import statements need the sideEffects override — transitive imports
from deep within the bundle are not bare imports and don't need resolution.
Skip enhanced-resolve for non-import-statement kinds to reduce overhead.
2026-04-03 18:11:37 +00:00
Karthik Kalyan 760ebf161b [world-vercel] align header names to x-vercel-workflow-* convention (#1602)
* update x-vercel-workflow-run-id and x-vercel-workflow-step-id

* Update dark-olives-fix.md

Signed-off-by: Karthik Kalyan <105607645+karthikscale3@users.noreply.github.com>

---------

Signed-off-by: Karthik Kalyan <105607645+karthikscale3@users.noreply.github.com>
2026-04-03 10:35:22 -07:00
Karthik Kalyan ce8a80eb82 [docs] Add vercel world consumer function security documentation (#1543) 2026-04-03 09:57:01 -07:00
Pranay Prakash 047c01bc15 Make start() types unknown when deploymentId is provided (#1367)
* fix: update types and documentation for start function overloads

Ensure types are 'unknown[]' and 'unknown' for 'deploymentId' and update exports and documentation.

Slack-Thread: https://vercel.slack.com/archives/C09G3EQAL84/p1773368990070059?thread_ts=1773368990.070059&cid=C09G3EQAL84
Co-authored-by: Pranay Prakash <1797812+pranaygp@users.noreply.github.com>

* fix: use generics in deploymentId overloads to avoid contravariance issue

Addresses PR review feedback: typed workflows like
WorkflowFunction<[string], number> were not assignable to
WorkflowFunction<unknown[], unknown> under strictFunctionTypes.
Changed to generic parameters while keeping Run<unknown> return type.
Also adds type-level tests for overload resolution.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* chore: add changeset for start() deploymentId type changes

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: v0 <v0[bot]@users.noreply.github.com>
Co-authored-by: Pranay Prakash <1797812+pranaygp@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 19:52:47 -07:00
Nathan Rajlich 44290785e1 fix(next): stop force-setting WORKFLOW_PUBLIC_MANIFEST=1 during next dev (#1597) 2026-04-02 22:49:14 +00:00
workflow-devkit-release-bot[bot] 45fd831b1d Version Packages (beta) (#1593) workflow@4.2.0-beta.76 2026-04-02 21:25:14 +00:00
Peter Wielander 136c1f4e97 [docs] Tidy world API docs and document new stream helpers (#1581) 2026-04-02 20:08:51 +00:00
Nathan Rajlich 7e33c62736 Rename 'Workflow Development Kit' / 'DevKit' to 'Workflow SDK' (#1595)
* Rename 'Workflow Development Kit' / 'DevKit' to 'Workflow SDK' across docs, code, and config

Follow-up to cdf90d5a38 (#1541)

* Fix missing </h1> closing tag and add article 'the' before 'Workflow SDK' in docs
2026-04-02 19:39:02 +00:00
Peter Wielander ef2218ab22 [world] Use zod/v4 in queue files to match @workflow/world schemas (#1588) 2026-04-02 12:38:13 -07:00
Peter Wielander c0f07a985c [ai] Fix fatal stream errors surfacing as [object Object] (#1589) 2026-04-02 12:37:15 -07:00
Peter Wielander 74c4cdb651 [web] Fix server crash on unmatched routes (#1590) 2026-04-02 10:57:41 -07:00
Nathan Rajlich a3d70353e5 docs: rename 'Complex Example' to 'Instance Methods as Steps' (#1592)
* docs: rename 'Complex Example' to 'Instance Methods as Steps' in serialization guide

Rework the section title and introductory copy to better reflect
the purpose: making classes with Node.js APIs / side effects
workflow-compatible by adding "use step" to instance methods.

* docs: clarify that the static requirement applies to serialization hooks

Make the callout explicitly name WORKFLOW_SERIALIZE and
WORKFLOW_DESERIALIZE so it doesn't read as a blanket restriction
on instance methods, which would contradict the 'Instance Methods
as Steps' section below.
2026-04-02 17:04:03 +00:00
workflow-devkit-release-bot[bot] 8462c5df89 Version Packages (beta) (#1563) workflow@4.2.0-beta.75 2026-04-01 16:08:49 -07:00
Peter Wielander 6dc1b78582 [core] Extend flow route duration to "max" and fail runs where replay takes too long (#1567) 2026-04-01 21:33:39 +00:00
Nathan Rajlich d38114bff1 fix: check target run capabilities before encrypting hook payloads (#1572)
* fix: check target run capabilities before encrypting hook payloads

When resumeHook()/resumeWebhook() is called on a newer deployment that
supports encryption, it would encode the payload with the 'encr' format.
If the target workflow run was created by an older deployment that
predates encryption support, the run would fail with:
  Error: Unknown serialization format: "encr". Known formats: devl

Add a capabilities table that maps @workflow/core versions to supported
serialization formats. Before encoding, resumeHook() now checks the
target run's workflowCoreVersion and suppresses encryption when the
run's deployment doesn't support it.

* address review: guard against invalid/non-string workflowCoreVersion

- Validate with semver.valid() before comparing, falling back to
  baseline formats for malformed version strings
- Add typeof guard at the call site in resumeHook() since
  executionContext is Record<string, any>
- Add tests for invalid version strings (dev, empty, partial, etc.)
- Add encryption commit reference to capabilities module header
2026-04-01 21:32:51 +00:00
Peter Wielander a98f8de53f [core] Combine initial run fetch, event fetch, and run_started event creation (#1569) 2026-04-01 14:23:29 -07:00
Lucas Ralph e574ad2107 [docs] Split World API docs into sub-pages, update skill.md (#1457)
Signed-off-by: Lucas Ralph <lucas.ralph@vercel.com>
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
2026-04-01 09:39:22 -07:00
comfuture 0e8a880b6b [nitro] Preserve workflow step registration side effects (#1386)
In Nitro/Nuxt local production builds, the generated workflow/steps.mjs bundle could be treated as a pure export provider when the virtual handler only imports { POST }. That allowed the step bundle's top-level registerStepFunction(...) calls to disappear from the final Nitro server bundle, which led to runtime failures like Step \"...\" not found when a queued step executes.

Signed-off-by: comfuture <comfuture@gmail.com>
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
2026-04-01 09:28:47 -07:00
Pranay Prakash 9cb1fc9482 docs: add webhook security disclaimer (#1574)
* docs: add webhook security disclaimer

* Apply suggestions from code review

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>

---------

Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Peter Wielander <mittgfu@gmail.com>
2026-03-31 18:28:30 -07:00
Peter Wielander 329cdb3e1b [world] Re-enqueue active runs on world restart (#1534) 2026-03-30 13:48:09 -07:00
workflow-devkit-release-bot[bot] 91ba457764 Version Packages (beta) (#1550) workflow@4.2.0-beta.74 2026-03-30 13:42:22 -07:00
Karthik Kalyan c488877727 [web] Switch web package stream reader to getStreamChunks (#1542)
* fix: switch web stream reader from readFromStream to getStreamChunksix

* add decrypt button for stream

* add decrypt button for stream

* add polling for streams tab

* add polling for streams tab

* add jsdoc

* address review comments
2026-03-30 13:11:49 -07:00