oscerd commented on PR #27185:
URL: https://github.com/apache/camel/pull/27185#issuecomment-5934704716
All review feedback on this PR is addressed and CI is green on
`77abcd745cd9`, so re-requesting review.
Summary of what changed since the first review round:
- The `contextualTuples` example no longer takes `team:${header.team}` from
a caller header. That was the page contradicting itself — the IMPORTANT block
three paragraphs below forbids exactly that, since a tuple that *grants* built
from caller input lets the caller assert the relationship being checked. The
team now comes from an exchange property the route's own token-validating step
set, and a comment draws the line between that and `object`, which legitimately
may come from the request.
- I swept the rest of the page and the integration tests for other granting
expressions fed from inbound headers. There were none, so it was a single
instance rather than a pattern.
- Two FQCNs replaced with imports per the project's import-style rule.
- Rebased onto current main (it had drifted 25 commits), full reactor `BUILD
SUCCESS`, 106 unit + 13 integration tests green.
To be explicit about the approval state rather than let it pass unremarked:
the only approval on this PR is from `gnodet-bot` and is AI-generated, as was
the review that found the doc defect. I am not treating that as the human
approval the project requires, so I will not merge this myself.
@davsclaus @gnodet @Croway — worth a human eye on the trust-model wording in
particular. The code change here lets an endpoint assert relationships that are
true for one request only, and the thing that keeps it safe is that both
options are endpoint-only and never read from the message. The docs are
load-bearing for that, which is why the self-contradicting example mattered
more than a typo would.
Note also that #27195 is open against the same component; whichever of the
two lands second needs a rebase, and the conflict shape is mapped in a comment
above.
_Claude Code on behalf of oscerd_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]