Skip to content

fix(api): prevent caching authenticated workflow variables - #8339

Merged
waleedlatif1 merged 1 commit into
stagingfrom
codex/workflow-variables-cache
Sep 26, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
codex/workflow-variables-cache

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Return workflow variables with Cache-Control: private, no-store so authenticated responses cannot be stored or reused by HTTP caches.
  • Remove the obsolete cache lifetime and ETag calculation.

Type of Change

  • Bug fix

Testing

  • bun run lint
  • bun run check:audits (51 passed)
  • bun run apps/sim/scripts/check-block-registry.ts origin/staging
  • bun run docs-manifest:check
  • bun run --cwd apps/sim type-check
  • bun run --cwd apps/sim test 'app/api/workflows/[id]/variables/route.test.ts' (2 passed)

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 26, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 26, 2026 9:08pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Changes cache headers on authenticated API endpoint.

The PR appears safe to merge; the response cache policy survives the app’s route handling, and no caller dependency on the removed headers was found.

Summary

The workflow variables GET response now uses Cache-Control: private, no-store and no longer emits a cache lifetime or ETag. No new actionable issue was identified.

Reviews (2) · Last reviewed commit: "fix(api): prevent caching authenticated ..."

Comment thread apps/sim/app/api/workflows/[id]/variables/route.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 5b667d7 into staging Sep 26, 2026
32 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/workflow-variables-cache branch September 26, 2026 21:18

This branch was previously deployed

1 inactive deployment
Preview — b9e6824c Deployed Sep 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant