2.1→3.1 diagram form_id→form_ids rename uses an overly broad str_replace
Problem/Motivation
Comprehensive ECA 3.1.x code review found eca.post_update.php:147 renames the diagram field with
str_replace('camunda:field name="form_id"', ...).
This rewrites every element field named form_id, not just the form-event restriction. Any BPMN element carrying an unrelated camunda:field name="form_id" (e.g. a nested data/message field coincidentally named form_id) is silently rewritten. The executable-config rename is correctly guarded by isset(); the diagram path is not, and nothing verifies the rename matched.
Behavior affected
Diagram round-trip inaccuracy for unrelated fields; the upgrade silently mutates config it did not intend to touch.
Proposed resolution
Scope the replacement to the start-event extension element (parse via the modeler/XPath and rename only on the node carrying the form event plugin), or assert at least one replacement occurred and fall back to unreadable-model handling otherwise.