You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: apps/docs/content/docs/workflows/blocks/function.mdx
+11-4Lines changed: 11 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -140,12 +140,19 @@ rather than returning part of what your code wrote.
140
140
</Callout>
141
141
142
142
<Callouttype="warn">
143
-
Returned files live with the execution rather than in your workspace, and a text
144
-
file containing a resolved secret value is refused rather than returned — there is
145
-
nowhere on an execution file to record that it carries one. Write such a file to a
146
-
workspace path instead, or keep the secret out of the output.
143
+
Returned workflow files live with the execution rather than in your workspace.
144
+
A file containing a literal protected secret value is refused. Keep secrets out of
145
+
returned files, or use an explicit workspace export that records their provenance.
147
146
</Callout>
148
147
148
+
When called directly with `sim tools execute function_execute`, generated files
149
+
belong to the authenticated user and have `context: "copilot"`. Download one with
150
+
`sim tools files download "<file.id>" --output-file ./result.txt` in the same
151
+
workspace context. Direct calls also check filenames and refuse files whose
152
+
secret provenance is uncertain, including binary output after a protected secret
153
+
was used. For code that needs no secrets, pass `secretScope: "selected"` and
154
+
`mountedSecrets: []` in the tool input.
155
+
149
156
## Language
150
157
151
158
JavaScript without imports runs in a fast local sandbox. JavaScript with `import` or `require`, Python, and Shell run in the configured remote sandbox provider.
`Sandbox output file "${name}" contains a resolved secret value and was not returned. Write the file without embedding secret values, or export it to a workspace file where its provenance can be recorded.`,
@@ -2192,22 +2232,46 @@ async function collectSandboxOutputFiles(args: {
`Sandbox output file "${name}" cannot be returned because its secret provenance is uncertain. Return a text file without secret values, or export it from a workflow that records file provenance.`,
0 commit comments