Skip to content

fix(pipeline): respect quotes when parsing template expressions - #538

Open
Agnik47 wants to merge 1 commit into
agentrhq:mainfrom
Agnik47:fix/pipeline-template-quoted-expressions
Open

Agnik47 wants to merge 1 commit into
agentrhq:mainfrom
Agnik47:fix/pipeline-template-quoted-expressions

Conversation

@Agnik47

@Agnik47 Agnik47 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

Pipeline template expressions (${{ ... }}) are parsed without regard to quotes, so two ordinary shapes render wrongly. There is no tracking issue; the repro is below.

Expression Before After
${{ 'https://x.test/' + item.id + '/' }} https://x.test/' + item.id + '/ (its own source text) https://x.test/7/
${{ 'x' === 'x' ? 'yes' : 'no' }} source text yes
${{ item.tags | join(' | ') }} the unjoined array, filter silently skipped a | b | c
${{ 'a|b' }} undefined a|b

Two causes in src/pipeline/template.ts:

  • The quoted-literal fast path matched anything that starts and ends with the same quote (/^(['"])(.*)\1$/), so a concatenation or ternary wrapped in string literals was returned as text instead of being evaluated.
  • Filters were split on every single |, including one inside a quoted string.

Changes

  • The fast path now only accepts a literal whose body contains neither its delimiter nor a backslash. Everything else falls through to the existing path lookup and VM evaluation, which also means escapes such as 'it\'s' are now evaluated properly.
  • Filter segments are split by a small quote-aware scanner. If a quote is unterminated (for example default(it's)), the quotes are not string delimiters, so it falls back to the previous split and behaviour is unchanged.

Type of Change

  • 🐛 Bug fix

Verification

  • 7 new tests in src/pipeline/template.test.ts; 5 fail on main, the other 2 pin behaviour that already worked
  • npx vitest run --project unit src/pipeline (108 pass)
  • npm run typecheck

A template expression that starts and ends with a string literal, such as
${{ 'https://x.test/' + item.id + '/' }}, matched the quoted-literal fast
path and rendered its own source text instead of being evaluated. A | inside
a quoted string, as in join(' | ') or 'a|b', was treated as a filter
separator, so the filter was silently skipped or the literal became undefined.

Limit the fast path to literals whose body has no delimiter or backslash,
and split filters with a quote-aware scanner that falls back to the plain
split when a quote is unterminated.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🟠 Maintainer review suggested — low confidence

The automated review could not reach a fully supported conclusion.

Limitations

  • Some automated findings could not be verified against the pull request diff.

This review is advisory and does not block merging.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants