Promotion Nomination Extend App example - #20
abhi-matti wants to merge 1 commit into
Conversation
| "type": "title", | ||
| "label": "View Promotion Nomination Details" | ||
| }, | ||
| "body": { |
There was a problem hiding this comment.
WidgetIdRequiredRule (ACTION)
Widget of type 'section' at body is missing required 'id' field.
Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)
| "children": [ | ||
| { | ||
| "enabled": false, | ||
| "type": "text", |
There was a problem hiding this comment.
WidgetIdRequiredRule (ACTION)
Widget of type 'fieldSet' at body->children[2]->type: fieldSet is missing required 'id' field.
Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)
| "footer": { | ||
| "type": "footer", | ||
| "children": [ | ||
| { |
There was a problem hiding this comment.
WidgetIdRequiredRule (ACTION)
Widget of type 'richText' at footer->children[0]->type: richText is missing required 'id' field.
Why: Ensures all widgets have an 'id' field set (structure validation for PMD and POD files)
| ], | ||
| "endPoints": [ | ||
| { | ||
| "name": "me", |
There was a problem hiding this comment.
EndpointFailOnStatusCodesRule (ACTION)
Inbound endpoint 'me' is missing required 'failOnStatusCodes' field.
Why: Ensures endpoints have failOnStatusCodes with minimum required codes 400 and 403
Suggested change:
"failOnStatusCodes": [{"code": 400}, {"code": 403}]
| }, | ||
| { | ||
| "_comment": "Retrieves logged-in manager's direct reports ", | ||
| "name": "getEmployeeList", |
There was a problem hiding this comment.
EndpointFailOnStatusCodesRule (ACTION)
Inbound endpoint 'getEmployeeList' is missing required 'failOnStatusCodes' field.
Why: Ensures endpoints have failOnStatusCodes with minimum required codes 400 and 403
Suggested change:
"failOnStatusCodes": [{"code": 400}, {"code": 403}]
| { | ||
| "name": "submitPromotion", | ||
| "baseUrlType": "app", | ||
| "url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>", |
There was a problem hiding this comment.
HardcodedApplicationIdRule (ACTION)
Hardcoded applicationId 'promotionNomination_rvylxm' found. Use site.applicationId instead.
Why: Detects hardcoded applicationId values that should be replaced with site.applicationId
| "url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>", | |
| "url": "<% 'https://api.workday.com/apps/' + site.applicationId + '/v1/promotionNominationBPEvents' %>", |
| { | ||
| "name": "submitPromotion", | ||
| "baseUrlType": "app", | ||
| "url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>", |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
Outbound endpoint 'submitPromotion' uses hardcoded *.workday.com URL: '<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "url": "<% 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>", | |
| "url": "<% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/promotionNominationBPEvents' %>", |
| 'description': 'Approval for Promotion Nomination', | ||
| 'businessProcessTarget': {'id': storePromotionNominationBO.id} | ||
| }; | ||
| console.info('zzzzzzzzzzz ' + payload.businessProcessTarget); |
There was a problem hiding this comment.
ScriptConsoleLogRule (ACTION)
File section 'outboundEndpoints[1]->name: submitPromotion->onSend' contains console.info statement. Remove debug statements from production code.
Why: Ensures scripts don't contain console statements (production code)
| console.info('zzzzzzzzzzz ' + payload.businessProcessTarget); | |
| // console.info('zzzzzzzzzzz ' + payload.businessProcessTarget); |
| @@ -0,0 +1,42 @@ | |||
| { | |||
There was a problem hiding this comment.
HardcodedApplicationIdRule (ACTION)
Hardcoded applicationId 'promotionNomination_rvylxm' found in AMD dataProvider. Use site.applicationId instead.
Why: Detects hardcoded applicationId values that should be replaced with site.applicationId
Suggested change:
site.applicationId
| "dataProviders": [ | ||
| { | ||
| "key": "workday-staffing", | ||
| "value": "https://api.workday.com/staffing/v7/" |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
AMD dataProvider 'workday-staffing' uses hardcoded *.workday.com URL: 'https://api.workday.com/staffing/v7/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "value": "https://api.workday.com/staffing/v7/" | |
| "value": "<% apiGatewayEndpoint + '/staffing/v7/' %>" |
| }, | ||
| { | ||
| "key": "workday-wql", | ||
| "value": "https://api.us.wcp.workday.com/wql/v1" |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
AMD dataProvider 'workday-wql' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/wql/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "value": "https://api.us.wcp.workday.com/wql/v1" | |
| "value": "<% apiGatewayEndpoint + '/wql/v1' %>" |
| }, | ||
| { | ||
| "key": "workday-common", | ||
| "value": "https://api.us.wcp.workday.com/common/v1" |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
AMD dataProvider 'workday-common' uses hardcoded *.workday.com URL: 'https://api.us.wcp.workday.com/common/v1'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "value": "https://api.us.wcp.workday.com/common/v1" | |
| "value": "<% apiGatewayEndpoint + '/common/v1' %>" |
| }, | ||
| { | ||
| "key": "workday-bp", | ||
| "value": "https://api.workday.com/businessProcess/v1/" |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
AMD dataProvider 'workday-bp' uses hardcoded *.workday.com URL: 'https://api.workday.com/businessProcess/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "value": "https://api.workday.com/businessProcess/v1/" | |
| "value": "<% apiGatewayEndpoint + '/businessProcess/v1/' %>" |
| }, | ||
| { | ||
| "key": "app", | ||
| "value": "https://api.workday.com/apps/promotionNomination_rvylxm/v1/" |
There was a problem hiding this comment.
HardcodedWorkdayAPIRule (ACTION)
AMD dataProvider 'app' uses hardcoded *.workday.com URL: 'https://api.workday.com/apps/promotionNomination_rvylxm/v1/'. Use apiGatewayEndpoint instead of hardcoded Workday URLs for regional awareness.
Why: Detects hardcoded *.workday.com URLs that should use apiGatewayEndpoint for regional awareness
| "value": "https://api.workday.com/apps/promotionNomination_rvylxm/v1/" | |
| "value": "<% apiGatewayEndpoint + '/apps/promotionNomination_rvylxm/v1/' %>" |
| "children": [ | ||
| { | ||
| "type": "richText", | ||
| "enabled": "false", |
There was a problem hiding this comment.
StringBooleanRule (ADVICE)
Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'.
Why: Ensures boolean values are not represented as strings 'true'/'false' but as actual booleans
| "enabled": "false", | |
| "enabled": false, |
| "label": "Promotion Cycle", | ||
| "type": "text", | ||
| "id": "promotionCycleWidget", | ||
| "value": "2026-Q1" |
There was a problem hiding this comment.
HubHardcodedPeriodLiteralRule (ADVICE)
"2026-Q1" is a hardcoded period or date. Every cycle someone has to edit and redeploy the app. Compute it from today's date (for example <% date:today %> and a small script), read it from an app attribute, or document it under "## Before you deploy" so readers know to change it.
Why: A date or period literal (like 2026-Q1) is hardcoded, so the example silently goes stale.
| "type": "footer", | ||
| "children": [ | ||
| { | ||
| "enabled": "false", |
There was a problem hiding this comment.
StringBooleanRule (ADVICE)
Field 'enabled' has string value 'false' instead of boolean false. Use boolean false instead of string 'false'.
Why: Ensures boolean values are not represented as strings 'true'/'false' but as actual booleans
| "enabled": "false", | |
| "enabled": false, |
| //Outbound endpoint that submits the BO | ||
|
|
||
|
|
||
| var obj = {:}; |
There was a problem hiding this comment.
ScriptVarUsageRule (ADVICE)
File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' uses 'var' declaration for variable 'obj'. Consider using 'let' or 'const' instead.
Why: Ensures scripts use 'let' or 'const' instead of 'var' (best practice)
| var obj = {:}; | |
| let obj = {:}; |
|
|
||
| var obj = {:}; | ||
|
|
||
| obj.add('nominee', (!empty selectedEmployeeWidget.selectedEntries[0].id) ? {'id':selectedEmployeeWidget.selectedEntries[0].id} : null); |
There was a problem hiding this comment.
ScriptComplexityRule (ADVICE)
File section 'outboundEndpoints[0]->name: storePromotionNominationBO->onSend' has complexity of 15 (max recommended: 10). Consider refactoring.
Why: Ensures scripts don't exceed complexity thresholds (max 10 cyclomatic complexity)
| obj.add('businessNeed', (!empty promotionBusNeedQ2.value) ? promotionBusNeedQ2.value : null); | ||
| obj.add('workerSuitRole', (!empty roleConsiderationQ3.value) ? roleConsiderationQ3.value : null); | ||
| self.data = obj; | ||
| console.info('Nomination payload is ' + json:asJSON(self.data)); |
There was a problem hiding this comment.
ScriptStringConcatRule (ADVICE)
Outbound endpoint 'storePromotionNominationBO' uses string concatenation with + operator: ''Nomination payload is ' + json:asJSONself.data'. Consider using PMD template strings with backticks and {{ }} syntax instead (e.g., Hello {{name}}!).
Why: Detects string concatenation with + operator - use PMD templates with backticks and {{ }} instead
Suggested change:
`Nomination payload is {{json:asJSONself.data}}`
Example auditAudited 25 to fix and 23 suggestion(s). Fix before merge
Suggestions (23, never block)
Run it yourself: ACTION items fail the Audit examples check. ADVICE never blocks. Maintainers can add the 2 finding(s) are file-level and appear only in this summary. |
What this PR adds or changes
Adds a new Workday Extend App example for the promotion nomination flow (
examples/promotion-nomination).Core Features
Checklist for new or changed examples
examples/node scripts/validate-examples.mjs --checkpassesnode scripts/audit-examples.mjs --changedpasses