oscerd commented on PR #27185:
URL: https://github.com/apache/camel/pull/27185#issuecomment-5934704716

   All review feedback on this PR is addressed and CI is green on 
`77abcd745cd9`, so re-requesting review.
   
   Summary of what changed since the first review round:
   
   - The `contextualTuples` example no longer takes `team:${header.team}` from 
a caller header. That was the page contradicting itself — the IMPORTANT block 
three paragraphs below forbids exactly that, since a tuple that *grants* built 
from caller input lets the caller assert the relationship being checked. The 
team now comes from an exchange property the route's own token-validating step 
set, and a comment draws the line between that and `object`, which legitimately 
may come from the request.
   - I swept the rest of the page and the integration tests for other granting 
expressions fed from inbound headers. There were none, so it was a single 
instance rather than a pattern.
   - Two FQCNs replaced with imports per the project's import-style rule.
   - Rebased onto current main (it had drifted 25 commits), full reactor `BUILD 
SUCCESS`, 106 unit + 13 integration tests green.
   
   To be explicit about the approval state rather than let it pass unremarked: 
the only approval on this PR is from `gnodet-bot` and is AI-generated, as was 
the review that found the doc defect. I am not treating that as the human 
approval the project requires, so I will not merge this myself.
   
   @davsclaus @gnodet @Croway — worth a human eye on the trust-model wording in 
particular. The code change here lets an endpoint assert relationships that are 
true for one request only, and the thing that keeps it safe is that both 
options are endpoint-only and never read from the message. The docs are 
load-bearing for that, which is why the self-contradicting example mattered 
more than a typo would.
   
   Note also that #27195 is open against the same component; whichever of the 
two lands second needs a rebase, and the conflict shape is mapped in a comment 
above.
   
   _Claude Code on behalf of oscerd_


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to