Skip to content

Promotion Nomination Extend App example - #20

Open
abhi-matti wants to merge 1 commit into
Workday:mainfrom
abhi-matti:promotion-nomination-example-submission
Open

abhi-matti wants to merge 1 commit into
Workday:mainfrom
abhi-matti:promotion-nomination-example-submission

Conversation

@abhi-matti

Copy link
Copy Markdown

What this PR adds or changes

Adds a new Workday Extend App example for the promotion nomination flow (examples/promotion-nomination).

Core Features

  • Manager Self-Service Nomination: Allows managers to select eligible direct reports, propose target job profiles, and submit structured promotion justifications.
  • Dynamic Worker Data Lookup: Uses WQL queries to automatically populate current job profile, tenure, and reporting hierarchy for selected direct reports.
  • Approval Workflow & Tracking: Routes submitted nominations to HR Business Partners and leadership for review, approval, or revision requests.

Checklist for new or changed examples

  • The example lives entirely in its own folder under examples/
  • node scripts/validate-examples.mjs --check passes
  • The README says what the artifact is, how to use it, and what to change before deploying it
  • No credentials, tenant names, or real personal data anywhere in the folder
  • node scripts/audit-examples.mjs --changed passes

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Example audit: 40 inline comment(s). The summary comment on this PR has the full list.

"type": "title",
"label": "View Promotion Nomination Details"
},
"body": {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WidgetIdRequiredRule (ACTION)

Widget of type 'section' at body is missing required 'id' field.

Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)

Read more

"children": [
{
"enabled": false,
"type": "text",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WidgetIdRequiredRule (ACTION)

Widget of type 'fieldSet' at body->children[2]->type: fieldSet is missing required 'id' field.

Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)

Read more

"footer": {
"type": "footer",
"children": [
{

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WidgetIdRequiredRule (ACTION)

Widget of type 'richText' at footer->children[0]->type: richText is missing required 'id' field.

Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)

Read more

],
"endPoints": [
{
"name": "me",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

EndpointFailOnStatusCodesRule (ACTION)

Inbound endpoint 'me' is missing required 'failOnStatusCodes' field.

Why: Ensures endpoints have failOnStatusCodes with minimum required codes 400 and 403

Suggested change:

"failOnStatusCodes": [{"code": 400}, {"code": 403}]

Read more

},
{
"_comment": "Retrieves logged-in manager's direct reports ",
"name": "getEmployeeList",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

EndpointFailOnStatusCodesRule (ACTION)

Inbound endpoint 'getEmployeeList' is missing required 'failOnStatusCodes' field.

Why: Ensures endpoints have failOnStatusCodes with minimum required codes 400 and 403

Suggested change:

"failOnStatusCodes": [{"code": 400}, {"code": 403}]

Read more

{
"name": "submitPromotion",
"baseUrlType": "app",
"url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedApplicationIdRule (ACTION)

Hardcoded applicationId 'promotionNomination_rvylxm' found. Use site.applicationId instead.

Why: Detects hardcoded applicationId values that should be replaced with site.applicationId

Suggested change
"url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>",
"url": "<% 'https://api.workday.com/apps/' + site.applicationId + '/v1/promotionNominationBPEvents' %>",

Read more

{
"name": "submitPromotion",
"baseUrlType": "app",
"url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

Outbound endpoint 'submitPromotion' uses hardcoded *.workday.com URL: '<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>",
"url": "<% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>",

Read more

'description': 'Approval for Promotion Nomination',
'businessProcessTarget': {'id': storePromotionNominationBO.id}
};
console.info('zzzzzzzzzzz ' + payload.businessProcessTarget);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ScriptConsoleLogRule (ACTION)

File section 'outboundEndpoints[1]->name: submitPromotion->onSend' contains console.info statement. Remove debug statements from production code.

Why: Ensures scripts don't contain console statements (production code)

Suggested change
console.info('zzzzzzzzzzz ' + payload.businessProcessTarget);
// console.info('zzzzzzzzzzz ' + payload.businessProcessTarget);

Read more

@@ -0,0 +1,42 @@
{

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedApplicationIdRule (ACTION)

Hardcoded applicationId 'promotionNomination_rvylxm' found in AMD dataProvider. Use site.applicationId instead.

Why: Detects hardcoded applicationId values that should be replaced with site.applicationId

Suggested change:

site.applicationId

Read more

"dataProviders": [
{
"key": "workday-staffing",
"value": "https://api.workday.com/staffing/v7/"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

AMD dataProvider 'workday-staffing' uses hardcoded *.workday.com URL: 'https://api.workday.com/staffing/v7/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"value": "https://api.workday.com/staffing/v7/"
"value": "<% apiGatewayEndpoint + '/staffing/v7/' %>"

Read more

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Example audit, continued (21 to 40 of 40).

},
{
"key": "workday-wql",
"value": "https://api.us.wcp.workday.com/wql/v1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

AMD dataProvider 'workday-wql' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/wql/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"value": "https://api.us.wcp.workday.com/wql/v1"
"value": "<% apiGatewayEndpoint + '/wql/v1' %>"

Read more

},
{
"key": "workday-common",
"value": "https://api.us.wcp.workday.com/common/v1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

AMD dataProvider 'workday-common' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/common/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"value": "https://api.us.wcp.workday.com/common/v1"
"value": "<% apiGatewayEndpoint + '/common/v1' %>"

Read more

},
{
"key": "workday-bp",
"value": "https://api.workday.com/businessProcess/v1/"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

AMD dataProvider 'workday-bp' uses hardcoded *.workday.com URL: 'https://api.workday.com/businessProcess/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"value": "https://api.workday.com/businessProcess/v1/"
"value": "<% apiGatewayEndpoint + '/businessProcess/v1/' %>"

Read more

},
{
"key": "app",
"value": "https://api.workday.com/apps/promotionNomination_rvylxm/v1/"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HardcodedWorkdayAPIRule (ACTION)

AMD dataProvider 'app' uses hardcoded *.workday.com URL: 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.

Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness

Suggested change
"value": "https://api.workday.com/apps/promotionNomination_rvylxm/v1/"
"value": "<% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/' %>"

Read more

"children": [
{
"type": "richText",
"enabled": "false",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

StringBooleanRule (ADVICE)

Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'.

Why: Ensures boolean values are not represented as strings 'true'/'false' but as actual booleans

Suggested change
"enabled": "false",
"enabled": false,

Read more

"label": "Promotion Cycle",
"type": "text",
"id": "promotionCycleWidget",
"value": "2026-Q1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HubHardcodedPeriodLiteralRule (ADVICE)

"2026-Q1" is a hardcoded period or date. Every cycle someone has to edit and redeploy the app. Compute it from today's date (for example <% date:today %> and a small script), read it from an app attribute, or document it under "## Before you deploy" so readers know to change it.

Why: A date or period literal (like 2026-Q1) is hardcoded, so the example silently goes stale.

Read more

"type": "footer",
"children": [
{
"enabled": "false",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

StringBooleanRule (ADVICE)

Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'.

Why: Ensures boolean values are not represented as strings 'true'/'false' but as actual booleans

Suggested change
"enabled": "false",
"enabled": false,

Read more

//Outbound endpoint that submits the BO


var obj = {:};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ScriptVarUsageRule (ADVICE)

File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' uses 'var' declaration for variable 'obj'. Consider using 'let' or 'const' instead.

Why: Ensures scripts use 'let' or 'const' instead of 'var' (best practice)

Suggested change
var obj = {:};
let obj = {:};

Read more


var obj = {:};

obj.add('nominee', (!empty selectedEmployeeWidget.selectedEntries[0].id) ? {'id':selectedEmployeeWidget.selectedEntries[0].id} : null);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ScriptComplexityRule (ADVICE)

File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' has complexity of 15 (max recommended: 10). Consider refactoring.

Why: Ensures scripts don't exceed complexity thresholds (max 10 cyclomatic complexity)

Read more

obj.add('businessNeed', (!empty promotionBusNeedQ2.value) ? promotionBusNeedQ2.value : null);
obj.add('workerSuitRole', (!empty roleConsiderationQ3.value) ? roleConsiderationQ3.value : null);
self.data = obj;
console.info('Nomination payload is ' + json:asJSON(self.data));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ScriptStringConcatRule (ADVICE)

Outbound endpoint 'storePromotionNominationBO' uses string concatenation with + operator: ''Nomination payload is ' + json:asJSONself.data'. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!).

Why: Detects string concatenation with + operator - use PMD templates with backticks and {{ }} instead

Suggested change:

`Nomination payload is {{json:asJSONself.data}}`

Read more

@github-actions

Copy link
Copy Markdown

The Audit examples check failed because of the items under Fix before merge. Push a fix and it re-runs automatically.

Example audit

Audited examples/promotion-nomination.

25 to fix and 23 suggestion(s).

Fix before merge

Where Rule What to change
examples/promotion-nomination/README.md HubExampleJsonRule README.md is missing. Copy examples/_template/README.md and fill in its sections.
examples/promotion-nomination/presentation/eventDetails.pmd line 42 WidgetIdRequiredRule Widget of type 'section' at body is missing required 'id' field.
examples/promotion-nomination/presentation/eventDetails.pmd line 48 WidgetIdRequiredRule Widget of type 'fieldSet' at body->children[2]->type: fieldSet is missing required 'id' field.
examples/promotion-nomination/presentation/eventDetails.pmd line 151 WidgetIdRequiredRule Widget of type 'richText' at footer->children[0]->type: richText is missing required 'id' field.
examples/promotion-nomination/presentation/managerNomination.pmd line 8 EndpointFailOnStatusCodesRule Inbound endpoint 'me' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 15 EndpointFailOnStatusCodesRule Inbound endpoint 'getEmployeeList' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 24 EndpointFailOnStatusCodesRule Inbound endpoint 'workerInfo' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 25 HardcodedWorkdayAPIRule Inbound endpoint 'workerInfo' uses hardcoded *.workday.com URL: 'https://api.workday.com/common/v1/workers/me'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.workday.com/common/v1/workers/me with <% apiGatewayEndpoint + '/common/v1/workers/me' %>.
examples/promotion-nomination/presentation/managerNomination.pmd line 31 EndpointFailOnStatusCodesRule Inbound endpoint 'getEmployeeData' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 40 EndpointFailOnStatusCodesRule Inbound endpoint 'getJobProfiles' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 51 EndpointFailOnStatusCodesRule Inbound endpoint 'getJobProfilesNoSearch' is missing required 'failOnStatusCodes' field. Suggested: "failOnStatusCodes": [{"code": 400}, {"code": 403}].
examples/promotion-nomination/presentation/managerNomination.pmd line 66 WidgetIdRequiredRule Widget of type 'fieldSet' at body is missing required 'id' field.
examples/promotion-nomination/presentation/managerNomination.pmd line 70 WidgetIdRequiredRule Widget of type 'section' at body->children[0]->type: section is missing required 'id' field.
examples/promotion-nomination/presentation/managerNomination.pmd line 78 WidgetIdRequiredRule Widget of type 'section' at body->children[0]->type: section->children[1]->type: section is missing required 'id' field.
examples/promotion-nomination/presentation/managerNomination.pmd line 269 WidgetIdRequiredRule Widget of type 'richText' at footer->children[0]->type: richText is missing required 'id' field.
examples/promotion-nomination/presentation/managerNomination.pmd line 306 ScriptConsoleLogRule File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' contains console.info statement. Remove debug statements from production code. Replace console.info('Nomination payload is ' + json:asJSON(self.data)); with // console.info('Nomination payload is ' + json:asJSON(self.data));.
examples/promotion-nomination/presentation/managerNomination.pmd line 321 HardcodedApplicationIdRule Hardcoded applicationId 'promotionNomination_rvylxm' found. Use site.applicationId instead. Replace promotionNomination_rvylxm with site.applicationId.
examples/promotion-nomination/presentation/managerNomination.pmd line 321 HardcodedWorkdayAPIRule Outbound endpoint 'submitPromotion' uses hardcoded *.workday.com URL: '<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents with <% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>.
examples/promotion-nomination/presentation/managerNomination.pmd line 329 ScriptConsoleLogRule File section 'outboundEndpoints[1]->name: submitPromotion->onSend' contains console.info statement. Remove debug statements from production code. Replace console.info('zzzzzzzzzzz ' + payload.businessProcessTarget); with // console.info('zzzzzzzzzzz ' + payload.businessProcessTarget);.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 1 HardcodedApplicationIdRule Hardcoded applicationId 'promotionNomination_rvylxm' found in AMD dataProvider. Use site.applicationId instead. Replace promotionNomination_rvylxm with site.applicationId.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 23 HardcodedWorkdayAPIRule AMD dataProvider 'workday-staffing' uses hardcoded *.workday.com URL: 'https://api.workday.com/staffing/v7/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.workday.com/staffing/v7/ with <% apiGatewayEndpoint + '/staffing/v7/' %>.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 27 HardcodedWorkdayAPIRule AMD dataProvider 'workday-wql' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/wql/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.us.wcp.workday.com/wql/v1 with <% apiGatewayEndpoint + '/wql/v1' %>.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 31 HardcodedWorkdayAPIRule AMD dataProvider 'workday-common' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/common/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.us.wcp.workday.com/common/v1 with <% apiGatewayEndpoint + '/common/v1' %>.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 35 HardcodedWorkdayAPIRule AMD dataProvider 'workday-bp' uses hardcoded *.workday.com URL: 'https://api.workday.com/businessProcess/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.workday.com/businessProcess/v1/ with <% apiGatewayEndpoint + '/businessProcess/v1/' %>.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 39 HardcodedWorkdayAPIRule AMD dataProvider 'app' uses hardcoded *.workday.com URL: 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness. Replace https://api.workday.com/apps/promotionNomination_rvylxm/v1/ with <% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/' %>.
Suggestions (23, never block)
Where Rule What to change
examples/promotion-nomination ArcaneAuditorWarning Arcane Auditor could not parse part of this folder, so some script rules were skipped: * LESS_THAN
examples/promotion-nomination/presentation/eventDetails.pmd line 153 StringBooleanRule Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'. Replace "enabled": "false" with "enabled": false.
examples/promotion-nomination/presentation/managerNomination.pmd line 19 ScriptStringConcatRule Inbound endpoint 'getEmployeeList' uses string concatenation with + operator: ''/data?query=' + string:urlEncode'SELECT worker FROM myDirectReports WHERE workerType in (d588c41a446c11de98360015c5e6daf6)''. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace '/data?query=' + string:urlEncode'SELECT worker FROM myDirectReports WHERE workerType in (d588c41a446c11de98360015c5e6daf6)' with /data?query={{string:urlEncode'SELECT worker FROM myDirectReports WHERE workerType in (d588c41a446c11de98360015c5e6daf6)'}}.
examples/promotion-nomination/presentation/managerNomination.pmd line 19 ScriptVarUsageRule File section 'inboundEndpoints[1]->name: getEmployeeList->url' uses 'var' declaration for variable 'query'. Consider using 'let' or 'const' instead. Replace var query with let query.
examples/promotion-nomination/presentation/managerNomination.pmd line 25 EndpointBaseUrlTypeRule Inbound endpoint 'workerInfo' is pointing to a Workday API, but not leveraging a baseUrlType. Extract Workday endpoints to shared AMD data providers to avoid duplication.
examples/promotion-nomination/presentation/managerNomination.pmd line 35 ScriptStringConcatRule Inbound endpoint 'getEmployeeData' uses string concatenation with + operator: ''SELECT worker, location, manager_Level01, hireDate, timeInJobProfile, jobProfile, jobTitle, lastPromotionDate FROM myDirectReports WHERE worker in "' + selectedWorkerIdQuery + '"''. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace 'SELECT worker, location, manager_Level01, hireDate, timeInJobProfile, jobProfile, jobTitle, lastPromotionDate FROM myDirectReports WHERE worker in "' + selectedWorkerIdQuery + '"' with SELECT worker, location, manager_Level01, hireDate, timeInJobProfile, jobProfile, jobTitle, lastPromotionDate FROM myDirectReports WHERE worker in "{{selectedWorkerIdQuery}}".
examples/promotion-nomination/presentation/managerNomination.pmd line 35 ScriptVarUsageRule File section 'inboundEndpoints[3]->name: getEmployeeData->url' uses 'var' declaration for variable 'query'. Consider using 'let' or 'const' instead. Replace var query with let query.
examples/promotion-nomination/presentation/managerNomination.pmd line 44 ScriptStringConcatRule Inbound endpoint 'getJobProfiles' uses string concatenation with + operator: ''SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter) WHERE jobProfileName startswith "' + instanceListQuery + '"''. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace 'SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter) WHERE jobProfileName startswith "' + instanceListQuery + '"' with SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter) WHERE jobProfileName startswith "{{instanceListQuery}}".
examples/promotion-nomination/presentation/managerNomination.pmd line 44 ScriptVarUsageRule File section 'inboundEndpoints[4]->name: getJobProfiles->url' uses 'var' declaration for variable 'query'. Consider using 'let' or 'const' instead. Replace var query with let query.
examples/promotion-nomination/presentation/managerNomination.pmd line 55 ScriptStringConcatRule Inbound endpoint 'getJobProfilesNoSearch' uses string concatenation with + operator: ''/data?query=' + string:urlEncode'SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter)''. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace '/data?query=' + string:urlEncode'SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter)' with /data?query={{string:urlEncode'SELECT jobProfileName, workdayID FROM allActiveJobProfiles (dataSourceFilter = defaultFilter)'}}.
examples/promotion-nomination/presentation/managerNomination.pmd line 55 ScriptVarUsageRule File section 'inboundEndpoints[5]->name: getJobProfilesNoSearch->url' uses 'var' declaration for variable 'query'. Consider using 'let' or 'const' instead. Replace var query with let query.
examples/promotion-nomination/presentation/managerNomination.pmd line 61 PMDSectionOrderingRule PMD sections are not in the correct order. Expected: [1. id, 2. securityDomains, 3. endPoints, 4. outboundData, 5. presentation] Actual: [1. id, 2. securityDomains, 3. endPoints, 4. presentation, 5. outboundData]
examples/promotion-nomination/presentation/managerNomination.pmd line 195 HubHardcodedPeriodLiteralRule "2026-Q1" is a hardcoded period or date. Every cycle someone has to edit and redeploy the app. Compute it from today's date (for example <% date:today %> and a small script), read it from an app attribute, or document it under "## Before you deploy" so readers know to change it.
examples/promotion-nomination/presentation/managerNomination.pmd line 270 StringBooleanRule Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'. Replace "enabled": "false" with "enabled": false.
examples/promotion-nomination/presentation/managerNomination.pmd line 289 ScriptVarUsageRule File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' uses 'var' declaration for variable 'obj'. Consider using 'let' or 'const' instead. Replace var obj with let obj.
examples/promotion-nomination/presentation/managerNomination.pmd line 291 ScriptComplexityRule File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' has complexity of 15 (max recommended: 10). Consider refactoring.
examples/promotion-nomination/presentation/managerNomination.pmd line 306 ScriptStringConcatRule Outbound endpoint 'storePromotionNominationBO' uses string concatenation with + operator: ''Nomination payload is ' + json:asJSONself.data'. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace 'Nomination payload is ' + json:asJSONself.data with Nomination payload is {{json:asJSONself.data}}.
examples/promotion-nomination/presentation/managerNomination.pmd line 321 EndpointBaseUrlTypeRule Outbound endpoint 'submitPromotion' is pointing to a Workday API, but not leveraging a baseUrlType. Extract Workday endpoints to shared AMD data providers to avoid duplication.
examples/promotion-nomination/presentation/managerNomination.pmd line 324 ScriptVarUsageRule File section 'outboundEndpoints[1]->name: submitPromotion->onSend' uses 'var' declaration for variable 'payload'. Consider using 'let' or 'const' instead. Replace var payload with let payload.
examples/promotion-nomination/presentation/managerNomination.pmd line 329 ScriptStringConcatRule Outbound endpoint 'submitPromotion' uses string concatenation with + operator: ''zzzzzzzzzzz ' + payload.businessProcessTarget'. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!). Replace 'zzzzzzzzzzz ' + payload.businessProcessTarget with zzzzzzzzzzz {{payload.businessProcessTarget}}.
examples/promotion-nomination/presentation/managerNomination.pmd line 343 EndpointNameLowerCamelCaseRule Outbound Endpoint 'ExtensionResponse' doesn't follow naming conventions. Must follow lowerCamelCase convention (e.g., 'myField', 'userName').
examples/promotion-nomination/presentation/promotionNomination_rvylxm.amd line 19 HubAppReferenceIdRule "promotionNomination_rvylxm" is the app reference id Workday generated for the original tenant (the _rvylxm suffix). Anyone who imports this example gets a different suffix. Add a "## Before you deploy" section to the README that tells readers to replace it, or reference it dynamically with site.applicationId in scripts.
examples/promotion-nomination/presentation/promotionNomination_rvylxm.smd line 2 HubAppReferenceIdRule "promotionNomination_rvylxm" is the app reference id Workday generated for the original tenant (the _rvylxm suffix). Anyone who imports this example gets a different suffix. Add a "## Before you deploy" section to the README that tells readers to replace it, or reference it dynamically with site.applicationId in scripts.

Run it yourself: ./scripts/install-arcane.sh once, then node scripts/audit-examples.mjs --changed. Rule explanations and fixes: docs/EXAMPLE_BEST_PRACTICES.md.

ACTION items fail the Audit examples check. ADVICE never blocks. Maintainers can add the audit-override label to merge with open ACTION items.

2 finding(s) are file-level and appear only in this summary.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant