Skip to content

fix(FOUR-32830): accept array form_data in rule expression assignees - #9008

Open
gproly wants to merge 12 commits into
developfrom
bugfix/FOUR-32830
Open

gproly wants to merge 12 commits into
developfrom
bugfix/FOUR-32830

Conversation

@gproly

@gproly gproly commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

getAssigneesFromExpression now handles array input from POST users_task_count, fixing 500 errors when REASSIGN_RESTRICT_TO_ASSIGNABLE_USERS is enabled.

https://processmaker.atlassian.net/browse/FOUR-32830

ci:deploy

getAssigneesFromExpression now handles array input from POST
users_task_count, fixing 500 errors when REASSIGN_RESTRICT_TO_ASSIGNABLE_USERS is enabled.

https://processmaker.atlassian.net/browse/FOUR-32830
Handle array input from POST users_task_count to prevent TypeError
when REASSIGN_RESTRICT_TO_ASSIGNABLE_USERS is enabled.

https://processmaker.atlassian.net/browse/FOUR-32830
@nolanpro

Copy link
Copy Markdown
Contributor

QA server K8S was successfully deployed https://ci-fe9ffd1065.engk8s.processmaker.net

…ay form_data

Accept array form_data in getAssigneesFromExpression to prevent
TypeError on users_task_count when REASSIGN_RESTRICT_TO_ASSIGNABLE_USERS is enabled.
Expand group assignees via getConsolidatedUsers, flatten manager_id, and evaluate
reassignment rules using BPMN assignment type instead of getAssignmentRule().

https://processmaker.atlassian.net/browse/FOUR-32830
@cursor

cursor Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes task reassignment and rule-expression assignee resolution (FEEL evaluation and stricter empty-list filtering), which can alter who appears in reassign dropdowns for existing processes.

Overview
Fixes FOUR-32830 by making reassignment user lookup work when REASSIGN_RESTRICT_TO_ASSIGNABLE_USERS is on and users_task_count POST sends form_data as an array (avoiding type errors on getAssigneesFromExpression).

ProcessRequestToken::getAssigneesFromExpression now accepts array or JSON form_data, merges it with request/instance variables, evaluates rules with feelExpression (replacing Symfony ExpressionLanguage), applies default rules only when no expression matches, expands group assignees, and still adds process managers.

UserController::getUsersTaskCount uses the BPMN assignment property for rule/process-variable branches, applies the assignable filter even when the resolved ID list is empty (no fallback to all users), and when assignable_for_task_id is set drops the authenticated user from the dropdown so self-reassign is blocked on the server.

The reassign UI removes client-side filtering of the current assignee; behavior is centralized in the API. Feature and model tests cover self-exclusion, rule expressions, empty matches, and groups.

Reviewed by Cursor Bugbot for commit 0fc151a. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread ProcessMaker/Models/ProcessRequestToken.php
Comment thread ProcessMaker/Models/ProcessRequestToken.php
…signees

Replace getAssignees plus in_array second pass with a single loop that
evaluates each rule via isAssignmentRuleMatch. This prevents unmatched
group rules from expanding when they share an assignee id with a matched
user rule, and avoids losing group members when manager_id collides with
sequential indexes from getConsolidatedUsers.

- Merge group users into userIds keyed by user id
- Reuse one ExpressionLanguage instance per loop
- Add unit tests for assignee id collision and manager id collision cases

https://processmaker.atlassian.net/browse/FOUR-32830
@nolanpro

nolanpro commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

QA server K8S was successfully deployed https://ci-fe9ffd1065.engk8s.processmaker.net

…sion reassignees

Evaluate rule_expression reassignment filtering even when form_data is missing
or empty, using persisted process request data as a fallback so expression rules
still match after a task has been reassigned.

- Always resolve rule_expression assignees in users_task_count when restriction is enabled
- Eager-load processRequest for expression variable resolution
- Add resolveExpressionVariables() to merge request data with submitted form_data
- Add unit and feature coverage for empty form_data group reassignment scenarios

https://processmaker.atlassian.net/browse/FOUR-32830

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread ProcessMaker/Http/Controllers/Api/UserController.php
…n has no matches

Fall back to persisted request data when form_data is empty so rule expression
reassignment keeps working after a task is reassigned, and always apply the
assignable filter even when no users match.

- Resolve expression variables from processRequest.data when form_data is empty
- Always evaluate rule_expression assignees when restriction is enabled
- Eager-load processRequest for expression variable resolution
- Apply whereIn whenever assignable filtering is active, including empty results
- Add tests for empty form_data fallback and no-match empty list scenarios

Fixes https://processmaker.atlassian.net/browse/FOUR-32830

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread ProcessMaker/Models/ProcessRequestToken.php
@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://ci-fe9ffd1065.engk8s.processmaker.net

…back

Default assignment rules were always treated as a match alongside expression
rules, so reassignment could include fallback users who would not receive
the task under the current data.

- Evaluate expression rules first and skip default rules in that pass
- Apply default rules only when no expression rule matches
- Extract isDefaultAssignmentRule() and appendAssignmentAssignees() helpers
- Add regression test for default exclusion when an expression rule matches

Fixes https://processmaker.atlassian.net/browse/FOUR-32830
@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://ci-fe9ffd1065.engk8s.processmaker.net

…lude session user

Evaluate assignment rule expressions with feelExpression() and resolve
variables from the process instance datastore, matching initial task
assignment behavior. Exclude the authenticated user from users_task_count
when assignable_for_task_id is provided and remove the duplicate
client-side filter from the reassign UI.

Refs: https://processmaker.atlassian.net/browse/FOUR-32830

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a9b76b. Configure here.

Comment thread ProcessMaker/Http/Controllers/Api/UserController.php
…r list

Clarify why users_task_count excludes the authenticated user when
assignable_for_task_id is present. This prevents self-reassignment in
the reassign modal without changing assignment rule evaluation.

Refs: https://processmaker.atlassian.net/browse/FOUR-32830
@gproly

gproly commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author
2026-09-25.10-41-53.mp4

@decisions-sonarqube

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants