fix(authz): bound retries for missing attribute values - #3989
Draft
strantalis wants to merge 2 commits into
Draft
Conversation
Signed-off-by: strantalis <strantalis@virtru.com>
Signed-off-by: strantalis <strantalis@virtru.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Contributor
|
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Changes
A single unknown FQN turned a 250-value lookup into 251 SDK calls. Split failed batches breadth-first, retain successful sub-batches, and skip missing singleton values while preserving per-resource denial behavior.
Limit failed batch probes to eight before falling back to singleton lookups. Sparse misses improve substantially; an all-missing batch is bounded at 258 calls versus the previous 251. Errors other than NotFound are returned without retries.
Layer 4 of 7 in the authorization performance stack. Review and merge from the bottom upward.
Checklist
Testing Instructions
Stack-wide validation:
make testwas attempted with Colima configured. The round-trip suite failed because its required platform server at127.0.0.1:8080was not running.make lintstopped because the configured Buf API token is invalid. Separatemake go-lintreported existing repository issues; the formatting issue in the new hierarchy test was corrected.make govulncheckreported vulnerabilities in the existing dependencies and the installed Go 1.26.3 standard library. This stack changes no dependency versions.