feat(apps): split AI tool and workflow action triggers in LogicFunction manifest (#20208)

## Summary

Replaces the bolted-on `isTool` + `toolInputSchema` fields on
`LogicFunctionManifest` with two distinct, opt-in triggers that align
with the existing `cron` / `databaseEvent` / `httpRoute` trigger
pattern:

- **`toolTriggerSettings`** — exposes the function as an AI tool (chat /
MCP / function calling). Uses standard JSON Schema (the format LLMs
natively understand).
- **`workflowActionTriggerSettings`** — exposes the function as a step
in the visual workflow builder. Uses Twenty's rich `InputSchema` so the
builder can render proper `FieldMetadataType`-aware editors, variable
pickers, labels, and an optional `outputSchema`.

A function can opt into none, one, or both. Each surface gets the schema
format appropriate for it.

### Why

`isTool: true` previously exposed the function as both an AI tool AND a
workflow node, with the same JSON Schema feeding both — but the workflow
builder really wants Twenty's `InputSchema` (with `CURRENCY`,
`RELATION`, `EMAILS`, etc.) and the AI surface really wants standard
JSON Schema. Today the workflow builder hacks around this by treating
JSON Schema as `InputSchema`, which silently breaks for any
non-primitive field type. Splitting the triggers fixes that and lets
each surface evolve independently.

### Migration

- **Fast** instance command adds the two new nullable columns.
- **Slow** instance command backfills `toolTriggerSettings` +
`workflowActionTriggerSettings` from `isTool=true` rows (preserving
today's both-surfaces behaviour) then drops the legacy columns.

### Stacked

Stacked on top of #20181. Merge that first, then this.

## Test plan

- [ ] CI green (oxlint, typecheck, jest, vitest)
- [ ] Run `--include-slow` upgrade against a workspace with existing
`isTool=true` logic functions; verify both new columns populated and old
columns dropped
- [ ] Verify AI chat sees migrated tool functions (Linear create-issue,
Exa search) and can call them with the JSON Schema
- [ ] Add an AI-tool function from the Settings UI (toggles
`toolTriggerSettings`) and verify it shows up in chat
- [ ] Add a workflow-action function from the Settings UI (toggles
`workflowActionTriggerSettings`) and verify it appears in the workflow
node picker
- [ ] In the workflow builder, edit a `LOGIC_FUNCTION` step and verify
input fields render (no more JSON-Schema-as-InputSchema hack)
- [ ] Try defining a function with no triggers in the SDK and verify
`defineLogicFunction` rejects it

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: martmull <martmull@hotmail.fr>
This commit is contained in:
Félix Malfait
2026-05-05 14:56:09 +02:00
committed by GitHub
parent 36452ecc8b
commit 53fdac1417
66 changed files with 820 additions and 357 deletions
@@ -28,13 +28,14 @@ export const fromLogicFunctionManifestToUniversalFlatLogicFunction = ({
builtHandlerPath: logicFunctionManifest.builtHandlerPath,
handlerName: logicFunctionManifest.handlerName,
checksum: logicFunctionManifest.builtHandlerChecksum,
toolInputSchema: logicFunctionManifest.toolInputSchema,
isTool: logicFunctionManifest.isTool ?? false,
cronTriggerSettings: logicFunctionManifest.cronTriggerSettings ?? null,
databaseEventTriggerSettings:
logicFunctionManifest.databaseEventTriggerSettings ?? null,
httpRouteTriggerSettings:
logicFunctionManifest.httpRouteTriggerSettings ?? null,
toolTriggerSettings: logicFunctionManifest.toolTriggerSettings ?? null,
workflowActionTriggerSettings:
logicFunctionManifest.workflowActionTriggerSettings ?? null,
isBuildUpToDate: true,
createdAt: now,
updatedAt: now,
@@ -0,0 +1,8 @@
// Refresh result returned by the app OAuth driver. Mirrors
// `ConnectedAccountTokens` from the central refresh manager but redeclared
// here so this engine-side driver has zero dependency on `modules/`.
export type AppOAuthTokens = {
accessToken: string;
refreshToken: string;
};
@@ -42,6 +42,48 @@ export class ApplicationVariableEntityService {
});
}
// Decrypted plaintext value. Server-side only — never expose via GraphQL.
// Used by trusted server flows that need the raw secret (e.g. exchanging an
// OAuth client secret with a third-party provider).
getRawValue(applicationVariable: ApplicationVariableEntity): string {
if (!applicationVariable.isSecret) {
return applicationVariable.value;
}
return this.secretEncryptionService.decrypt(applicationVariable.value);
}
async findOneByKey({
applicationId,
key,
}: {
applicationId: string;
key: string;
}): Promise<ApplicationVariableEntity | null> {
return this.applicationVariableRepository.findOne({
where: { applicationId, key },
});
}
async getRawValueByKeyOrThrow({
applicationId,
key,
}: {
applicationId: string;
key: string;
}): Promise<string> {
const variable = await this.findOneByKey({ applicationId, key });
if (!isDefined(variable)) {
throw new ApplicationVariableEntityException(
`Application variable "${key}" not found for application ${applicationId}`,
ApplicationVariableEntityExceptionCode.APPLICATION_VARIABLE_NOT_FOUND,
);
}
return this.getRawValue(variable);
}
async update({
key,
plainTextValue,