fix: escape commit message in notify-ave-site client-payload - #145
Merged
Merged
Conversation
The workflow interpolated github.event.head_commit.message directly into a JSON string literal via string substitution. Multi-line commit messages (e.g. any commit with a trailer, which is most of them in this repo) contain raw newlines, which are invalid inside a JSON string literal unless escaped -- every run with a multi-line commit message failed the dispatch with "Bad control character in string literal in JSON". Switched to toJSON(), which properly escapes newlines and quotes and already returns a quoted string, so the surrounding literal quotes around that field are removed. This was masked until now by a separate, unrelated failure: the AVE_SITE_DEPLOY_TOKEN secret didn't exist at all, so every run failed earlier at token validation before ever reaching the JSON payload. Confirmed via re-run after the secret was added: token error gone, this JSON error is what surfaced next.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Notify ave-site on records updateworkflow, which has been failing on every trigger since at least 2026-07-13.AVE_SITE_DEPLOY_TOKENdidn't exist as a repo secret at all -- every run failed at token validation ("Parameter token or opts.auth is required") before ever reaching the payload. Now added (not part of this PR, done directly in repo settings).client-payloadinterpolatesgithub.event.head_commit.messagedirectly into a JSON string via"${{ ... }}". Multi-line commit messages (i.e. any commit with a trailer -- most commits in this repo) contain raw newlines, invalid inside a JSON string literal unless escaped, so the dispatch failed withBad control character in string literal in JSON.${{ toJSON(github.event.head_commit.message) }}, which properly escapes newlines/quotes and already returns a quoted string, so the surrounding literal quotes are removed for that field.Test plan
python3 -c "import yaml; yaml.safe_load(...)")main, confirm the nextrecords/**orschema/**push triggers a green run (previously reproduced the JSON error viagh run rerunagainst a real multi-line commit message on the current, unfixed workflow)