fix(policy): narrow authorization attribute lookups - #3986
Draft
strantalis wants to merge 1 commit into
Draft
Conversation
Signed-off-by: strantalis <strantalis@virtru.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Contributor
|
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Changes
GetEntitleableAttributesByFqnswas using the general attribute query, which hydrated unrelated values, mappings, grants, and keys before issuing its targeted subject-mapping query. Add an authorization-specific SQL query that selects requested values and the ordered active siblings required for hierarchy evaluation.Preserve normalization, inactive-value errors, missing-value errors, hierarchy order, namespace identity, and allow-traversal behavior. General attribute reads and key mapping lookups continue using their existing queries. No schema migration or public protocol change is needed.
This addresses the default decision path exercised by DSPX-4625. It is separate from the paginated
ListSubjectMappingsoptimization.Layer 1 of 7 in the authorization performance stack. Review and merge from the bottom upward.
Checklist
Testing Instructions
GetEntitleableAttributesByFqnsintegration tests, passed.make policy-sql-gen;make fmtpassed.Stack-wide validation:
make testwas attempted with Colima configured. The round-trip suite failed because its required platform server at127.0.0.1:8080was not running.make lintstopped because the configured Buf API token is invalid. Separatemake go-lintreported existing repository issues; the formatting issue in the new hierarchy test was corrected.make govulncheckreported vulnerabilities in the existing dependencies and the installed Go 1.26.3 standard library. This stack changes no dependency versions.