Findings for a workload's RAW composeFile value — the base64:<…> payload
or plain inline text. This is the entry point every caller should use: it
owns the decode, so a payload that is not valid base64 becomes a normal
STACK_COMPOSE_PARSE_FAILED finding carrying the application, workload and
file, rather than a raw DOMException code=5 "Invalid character" thrown out
of whatever happened to be decoding.
That distinction is load-bearing: loadStackFile promises never to throw
for a compose problem so a broken stack can still be inspected and TORN
DOWN, and a bare decode broke exactly that promise for a truncated payload
out of a rendered catalog template.
Findings for a workload's RAW
composeFilevalue — thebase64:<…>payload or plain inline text. This is the entry point every caller should use: it owns the decode, so a payload that is not valid base64 becomes a normalSTACK_COMPOSE_PARSE_FAILEDfinding carrying the application, workload and file, rather than a rawDOMException code=5 "Invalid character"thrown out of whatever happened to be decoding.That distinction is load-bearing:
loadStackFilepromises never to throw for a compose problem so a broken stack can still be inspected and TORN DOWN, and a bare decode broke exactly that promise for a truncated payload out of a rendered catalog template.