Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

feat: add potential v2 breaking change logs for Expand and ListUsers#3182

Merged
Vic-Dev merged 18 commits into
mainopenfga/openfga:mainfrom
feat/add-logs-for-Expand-and-ListUsers-resolution-changesopenfga/openfga:feat/add-logs-for-Expand-and-ListUsers-resolution-changesCopy head branch name to clipboard
Jul 9, 2026
Merged

feat: add potential v2 breaking change logs for Expand and ListUsers#3182
Vic-Dev merged 18 commits into
mainopenfga/openfga:mainfrom
feat/add-logs-for-Expand-and-ListUsers-resolution-changesopenfga/openfga:feat/add-logs-for-Expand-and-ListUsers-resolution-changesCopy head branch name to clipboard

Conversation

@Vic-Dev

@Vic-Dev Vic-Dev commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Description

What problem is being solved?

Adds observability for potential v1 → v2 (weighted-graph) resolution breaking changes on the ListUsers and Expand endpoints, mirroring the Check-side logs added in #3149.

Note: Expand has no difference in behaviour for self_referential_userset from v1 to v2.

References

Review Checklist

  • I have clicked on "allow edits by maintainers".
  • I have added documentation for new/changed functionality in this PR or in a PR to openfga.dev [Provide a link to any relevant PRs in the references section above]
  • The correct base branch is being used, if not main
  • I have added tests to validate that the change in functionality is working as expected

Summary by CodeRabbit

  • New Features
    • Added structured diagnostic warning logs for potential v2 (weighted-graph) resolution breaking changes in Expand and ListUsers, including a computed reason.
    • Introduced centralized logic to compute and confirm divergence reasons for Check, Expand, and ListUsers.
  • Bug Fixes
    • Aligned Check’s breaking-change warning reason computation for userset-shaped queries.
  • Documentation
    • Updated the changelog under Unreleased to reflect the new diagnostic logging.
  • Tests
    • Added/updated end-to-end tests validating the warning message and that the logged reason matches expected outcomes.

@coderabbitai

coderabbitai Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Shared v2breaking reason detection was extracted and wired into Check, Expand, and ListUsers, with confirmation helpers, warning logs, tests, and a changelog note added around the new diagnostics.

Changes

v2 breaking-change diagnostics

Layer / File(s) Summary
Reason detection core
pkg/server/commands/v2breaking/v2breaking.go
Defines shared reason constants and helpers that derive Check, Expand, and ListUsers divergence reasons from rewrites, aliases, and typed-wildcard reachability.
Response confirmation helpers
pkg/server/commands/v2breaking/v2breaking.go
Adds helpers that confirm inferred reasons against ListUsers responses and Expand trees, including recursive alias detection.
Check integration
pkg/server/check.go, pkg/server/check_test.go
Server.Check now uses v2breaking.CheckReason, removes the local divergence helper code, and the test validates the shared reason path.
Expand warning flow
pkg/server/expand.go, pkg/server/expand_test.go
Server.Expand captures the query response, checks the inferred reason against the returned tree, and logs a warning when confirmed; the new test covers matching and non-matching cases.
ListUsers warning flow
pkg/server/list_users.go, pkg/server/list_users_test.go, CHANGELOG.md
Server.ListUsers checks each filter after the query, confirms matching results, logs warnings, and adds the new table-driven test and changelog note.

Estimated code review effort: 4 (Complex) | ~60 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 76.92% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding v2 breaking-change logs for Expand and ListUsers.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/add-logs-for-Expand-and-ListUsers-resolution-changes

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jun 24, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 7.27848% with 293 lines in your changes missing coverage. Please review.
✅ Project coverage is 80.46%. Comparing base (69efbd9) to head (d372e07).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
pkg/server/commands/v2breaking/v2breaking.go 0.00% 289 Missing ⚠️
pkg/server/check.go 0.00% 2 Missing ⚠️
pkg/server/expand.go 84.62% 1 Missing and 1 partial ⚠️

❌ Your project status has failed because the head coverage (80.46%) is below the target coverage (85.00%). You can increase the head coverage or adjust the target coverage.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3182      +/-   ##
==========================================
- Coverage   81.50%   80.46%   -1.04%     
==========================================
  Files         201      202       +1     
  Lines       22286    22549     +263     
==========================================
- Hits        18163    18141      -22     
- Misses       3331     3616     +285     
  Partials      792      792              
Flag Coverage Δ
matrix 84.93% <ø> (ø)
storage 86.23% <ø> (ø)
unit 79.29% <7.28%> (-1.26%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Vic-Dev
Vic-Dev marked this pull request as ready for review June 26, 2026 19:53
@Vic-Dev
Vic-Dev requested a review from a team as a code owner June 26, 2026 19:53
Copilot AI review requested due to automatic review settings June 26, 2026 19:53
@coderabbitai

coderabbitai Bot commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{"name":"HttpError","status":500,"request":{"method":"PATCH","url":"https://api.github.com/repos/openfga/openfga/issues/comments/4793481748","headers":{"accept":"application/vnd.github.v3+json","user-agent":"octokit.js/0.0.0-development octokit-core.js/7.0.6 Node.js/24","content-type":"application/json; charset=utf-8"},"body":{"body":"<!-- This is an auto-generated comment: summarize by coderabbit.ai -->\n<!-- review_stack_entry_start -->\n\n[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/openfga/openfga/pull/3182?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)\n\n<!-- review_stack_entry_end -->\n<!-- This is an auto-generated comment: review in progress by coderabbit.ai -->\n\n> [!NOTE]\n> Currently processing new changes in this PR. This may take a few minutes, please wait...\n> \n> <details>\n> <summary>⚙️ Run configuration</summary>\n> \n> **Configuration used**: Path: .coderabbit.yaml\n> \n> **Review profile**: CHILL\n> \n> **Plan**: Pro\n> \n> **Run ID**: `7292c70f-81f1-4959-93af-9284e2e93ea2`\n> \n> </details>\n> \n> <details>\n> <summary>📥 Commits</summary>\n> \n> Reviewing files that changed from the base of the PR and between dcaccbff8b155f73ce497992fefaa418f1d1d24c and 421b0dba74b01369ca2b005922dbf7645c9578ac.\n> \n> </details>\n> \n> <details>\n> <summary>📒 Files selected for processing (7)</summary>\n> \n> * `pkg/server/check.go`\n> * `pkg/server/check_test.go`\n> * `pkg/server/commands/v2breaking/v2breaking.go`\n> * `pkg/server/expand.go`\n> * `pkg/server/expand_test.go`\n> * `pkg/server/list_users.go`\n> * `pkg/server/list_users_test.go`\n> \n> </details>\n> \n> ```ascii\n>  _____________________________________________________________________________________\n> < All idioms must be learned. Good idioms only need to be learned once. - Alan Cooper >\n>  -------------------------------------------------------------------------------------\n>   \\\n>    \\   (\\__/)\n>        (•ㅅ•)\n>        /   づ\n> ```\n\n<!-- end of auto-generated comment: review in progress by coderabbit.ai -->\n\n<!-- finishing_touch_checkbox_start -->\n\n<details>\n<summary>✨ Finishing Touches</summary>\n\n<details>\n<summary>📝 Generate docstrings</summary>\n\n- [ ] <!-- {\"checkboxId\": \"7962f53c-55bc-4827-bfbf-6a18da830691\"} --> Create stacked PR\n- [ ] <!-- {\"checkboxId\": \"3e1879ae-f29b-4d0d-8e06-d12b7ba33d98\"} --> Commit on current branch\n\n</details>\n<details>\n<summary>🧪 Generate unit tests (beta)</summary>\n\n- [ ] <!-- {\"checkboxId\": \"f47ac10b-58cc-4372-a567-0e02b2c3d479\", \"radioGroupId\": \"utg-output-choice-group-unknown_comment_id\"} -->   Create PR with unit tests\n- [ ] <!-- {\"checkboxId\": \"6ba7b810-9dad-11d1-80b4-00c04fd430c8\", \"radioGroupId\": \"utg-output-choice-group-unknown_comment_id\"} -->   Commit unit tests in branch `feat/add-logs-for-Expand-and-ListUsers-resolution-changes`\n\n</details>\n\n</details>\n\n<!-- finishing_touch_checkbox_end -->\n<!-- tips_start -->\n\n---\n\nThanks for using [CodeRabbit](https://coderabbit.ai?utm_source=oss&utm_medium=github&utm_campaign=openfga/openfga&utm_content=3182)! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.\n\n<details>\n<summary>❤️ Share</summary>\n\n- [X](https://twitter.com/intent/tweet?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A&url=https%3A//coderabbit.ai)\n- [Mastodon](https://mastodon.social/share?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A%20https%3A%2F%2Fcoderabbit.ai)\n- [Reddit](https://www.reddit.com/submit?title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&text=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code.%20Check%20it%20out%3A%20https%3A//coderabbit.ai)\n- [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fcoderabbit.ai&mini=true&title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&summary=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code)\n\n</details>\n\n\n<sub>Comment `@coderabbitai help` to get the list of available commands.</sub>\n\n<!-- tips_end -->"},"request":{"retryCount":3,"signal":{},"retries":3,"retryAfter":16}}}

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds server-side warning logs to help operators detect potential request shapes where behavior may diverge between the current v1 resolution and a future v2 (weighted-graph) resolution for ListUsers and Expand, mirroring prior Check-side observability and consolidating the shape-detection logic into a shared v2breaking package.

Changes:

  • Emit structured warn logs for potential v2 breaking-change shapes on ListUsers and Expand, including store/model/request context and a reason.
  • Introduce pkg/server/commands/v2breaking to centralize divergence “shape” detection and response-side confirmation helpers.
  • Add end-to-end server tests that validate the new breaking-change logs for ListUsers and Expand; refactor Check to use the shared v2breaking.CheckReason.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
pkg/server/list_users.go Adds post-response warn logging for potential v2-breaking ListUsers shapes using v2breaking.
pkg/server/list_users_test.go Adds an end-to-end test asserting ListUsers breaking-change log emission across shape cases.
pkg/server/expand.go Adds post-response warn logging for potential v2-breaking Expand shapes using v2breaking.
pkg/server/expand_test.go Adds a new end-to-end test asserting Expand breaking-change log emission across shape cases.
pkg/server/commands/v2breaking/v2breaking.go New shared logic for detecting divergence shapes and confirming via response content/tree.
pkg/server/check.go Switches Check-side reason detection to v2breaking.CheckReason and adjusts log text.
pkg/server/check_test.go Updates breaking-change-reason tests to use v2breaking.CheckReason.

Comment thread pkg/server/list_users_test.go Outdated
Comment thread pkg/server/list_users_test.go Outdated
Comment thread pkg/server/expand_test.go Outdated
Comment thread pkg/server/expand_test.go Outdated
Comment thread pkg/server/expand_test.go Outdated
Comment thread pkg/server/commands/v2breaking/v2breaking.go
Comment thread pkg/server/check.go

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🧹 Nitpick comments (2)
pkg/server/expand_test.go (1)

293-293: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Remove the leftover stdout debug print.

Line 293 writes the full response to test output, but the test never asserts on it. This will just add noise to local and CI runs.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/server/expand_test.go` at line 293, Remove the leftover stdout debug
print in expand_test.go: the fmt.Printf in the test is writing the full response
to output without any assertion, so delete that debug statement and keep the
test focused on validating behavior through assertions only.
pkg/server/check.go (1)

122-129: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Update the stale helper reference in the comment.

Line 123 still points readers to breakingChangeReason, but the implementation now delegates to v2breaking.CheckReason.

Proposed cleanup
-			// Flag potential v2Check resolution breaking changes for userset requests.
-			// See breakingChangeReason for the scenarios we detect.
+			// Flag potential v2 Check resolution breaking changes for userset requests.
+			// See v2breaking.CheckReason for the scenarios we detect.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/server/check.go` around lines 122 - 129, Update the stale comment
reference in the check flow so it points to the current helper used by the
logic. In the v2 check warning path inside check.go, replace the mention of
breakingChangeReason with v2breaking.CheckReason so the comment matches the
implementation and guides readers to the right symbol.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CHANGELOG.md`:
- Line 12: The changelog entry has a malformed PR link because the reference
text and URL are separated by a space, so it will not render as a clickable
Markdown link. Update the affected CHANGELOG.md entry to use the standard linked
PR reference format for the `#3182` citation, keeping the rest of the release note
text unchanged.

In `@pkg/server/commands/v2breaking/v2breaking.go`:
- Around line 126-135: The v2 breaking-reason selection in v2breaking.go is
returning ReasonAliasUserset before checking computed/TTU cases, which can
suppress Expand warnings when alias confirmation is unavailable. Update the
decision flow in the relevant reason-selection logic (including the duplicated
block around the later occurrence) so rewriteContainsAnyComputedUserset and
rewriteContainsAnyTTU are evaluated before isAliasedDirectlyRelatedUserset, or
so all candidate reasons are considered until one is actually confirmed by an
aliased userset leaf.
- Around line 228-252: Prioritize the exclusion rewrite reason before the
response-specific ListUsers reasons in the v2breaking reason selection logic. In
the function that checks `filterRelation`, `usersetAliasesTargetRelation`,
`rewriteContainsComputedUserset`, `rewriteContainsTTUForUser`, and
`rewriteContainsDifference`, move the `rewriteContainsDifference` branch ahead
of the self/alias/computed/TTU checks so `ReasonUsersetWithExclusion` wins
first. Apply the same ordering fix in the other matching block referenced by the
comment so exclusion-related warnings are not suppressed by more specific
userset reasons.
- Around line 521-560: The wildcard check in branchAcceptsWildcard is
incorrectly marking objectType#relation as visited before traversing structural
rewrite nodes, which causes Union/Intersection/Difference children to
short-circuit and miss typed wildcards. Move the visited guard so it is applied
only when following relation edges through ComputedUserset and TupleToUserset
recursion, not for the current relation itself; keep the structural cases in
branchAcceptsWildcard free to evaluate all children, and apply the same
path-scoped visited handling to the TTU recursion target.

In `@pkg/server/list_users_test.go`:
- Around line 664-668: The test setup in the list users helper is overriding an
explicitly provided empty tuple slice with default seed data, so empty-store
cases are not actually tested. Update the tuple initialization logic in the
helper that builds the store fixtures so defaults are only injected when the
caller did not supply tuples at all, and preserve an explicit empty slice as
empty; this should keep the scenarios in the list users tests exercising the
intended empty-store behavior.

---

Nitpick comments:
In `@pkg/server/check.go`:
- Around line 122-129: Update the stale comment reference in the check flow so
it points to the current helper used by the logic. In the v2 check warning path
inside check.go, replace the mention of breakingChangeReason with
v2breaking.CheckReason so the comment matches the implementation and guides
readers to the right symbol.

In `@pkg/server/expand_test.go`:
- Line 293: Remove the leftover stdout debug print in expand_test.go: the
fmt.Printf in the test is writing the full response to output without any
assertion, so delete that debug statement and keep the test focused on
validating behavior through assertions only.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 5bee32ce-1a41-4931-b289-e6542d861a85

📥 Commits

Reviewing files that changed from the base of the PR and between dcaccbf and ab7b96a.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • pkg/server/check.go
  • pkg/server/check_test.go
  • pkg/server/commands/v2breaking/v2breaking.go
  • pkg/server/expand.go
  • pkg/server/expand_test.go
  • pkg/server/list_users.go
  • pkg/server/list_users_test.go

Comment thread CHANGELOG.md Outdated
Comment thread pkg/server/commands/v2breaking/v2breaking.go Outdated
Comment thread pkg/server/commands/v2breaking/v2breaking.go
Comment thread pkg/server/commands/v2breaking/v2breaking.go
Comment thread pkg/server/list_users_test.go Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 3 comments.

Comment thread pkg/server/check.go
Comment thread pkg/server/expand.go
Comment thread CHANGELOG.md Outdated
Comment thread pkg/server/commands/v2breaking/v2breaking.go Outdated
Comment thread pkg/server/commands/v2breaking/v2breaking.go
@Vic-Dev
Vic-Dev enabled auto-merge (squash) July 9, 2026 19:01
@Vic-Dev
Vic-Dev merged commit 46b1d53 into main Jul 9, 2026
38 of 44 checks passed
@Vic-Dev
Vic-Dev deleted the feat/add-logs-for-Expand-and-ListUsers-resolution-changes branch July 9, 2026 19:29
fredrikaverpil added a commit to fredrikaverpil/openfga that referenced this pull request Jul 12, 2026
Add support for exporting logs via OTLP, allowing integration with any
OpenTelemetry-compatible backend (Grafana Loki, Datadog, GCP Cloud
Logging, etc.).

When log.otlp.enabled is set, logs are exported via OTLP in addition to
stdout. The otelzap bridge attaches span context (trace ID, span ID) to
each log record, enabling log-trace correlation in backends that
support it.

Configuration mirrors the trace configuration shape: the standard OTel
env vars (OTEL_EXPORTER_OTLP_LOGS_ENDPOINT, OTEL_EXPORTER_OTLP_ENDPOINT)
only answer where logs are sent, while the explicit OpenFGA flag
(log.otlp.enabled / --log-otlp-enabled / OPENFGA_LOG_OTLP_ENABLED)
answers whether to export at all — so a cluster that injects the
generic endpoint variable for tracing does not silently start exporting
logs on upgrade.

zap's production sampling is applied outside the tee, so the keep/drop
decision is made once, before fan-out: stdout and OTLP receive the same
deterministically sampled stream and collector egress stays bounded
during log storms.

Changes:
- Add otelzap bridge core backed by an OTLP log provider
  (internal/telemetry/logging.go)
- Add WithOTELCore logger option that tees log entries to the bridge.
  The bridge core is capped to the configured log level, the stdout
  core strips the bridge-only context field via contextFilterCore, and
  the sampler wraps the tee (pkg/logger/logger.go)
- Attach the context field in the *WithContext logging methods only
  when an OTEL core is configured, and use those methods in the gRPC
  logging interceptor so the bridge can extract span context
  (pkg/middleware/logging/logging.go)
- Add config: log.otlp.enabled, log.otlp.endpoint, log.otlp.tls.enabled
  with OPENFGA_LOG_OTLP_* env vars and OTEL_EXPORTER_OTLP_* endpoint
  fallbacks (pkg/server/config/config.go, cmd/run/, .config-schema.json)

feat: add potential v2 breaking change logs for Expand and ListUsers (openfga#3182)
release: update changelog for release 1.18.1 (openfga#3188)
release: Update changelog to prep for 1.18.1 release (openfga#3186)
test: fix flaky TestV2CheckWithIteratorCache_HigherConsistencyBypassesCache (openfga#3061)

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Merge commit from fork

* test reproducing ListUsers report

* implement fix

* additional test with 3 operands
fix: match IPv4-mapped IPv6 addresses in the in_cidr condition (openfga#3181)

Signed-off-by: kanywst <niwatakuma@icloud.com>
fix: use deterministic proto marshaling for stored authorization models (openfga#3171)
chore: create draft release and publish after provenance succeeds for immutable tags/releases (openfga#3178)
docs: fix changelog entry (openfga#3177)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
feat: add v2Check logs for resolution breaking change (openfga#3149)
feat: BatchCheck uses v2Check when ExperimentalWeightedGraphCheck is enabled (openfga#3154)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: update changelog to add CVE identifiers for recent fixes (openfga#3176)
chore: update todo comment string in migration guide (openfga#3175)
release: update changelog for release `v1.18.0` (openfga#3174)

Co-authored-by: adriantam <adrian.tam@okta.com>
Merge commit from fork

* fix(authn): require issuer and audience when OIDC authn is enabled

Enforce configuration authn.oidc.audience and authn.oidc.issuer when
`authn.method` is set to `oidc`.

* fixed based on code review feedback

* fix: adding comments + test case on empty space for audience

* update based on code review feedback

* Update CHANGELOG.md

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>

* update changelog

* Update CHANGELOG.md

---------

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Merge commit from fork

* fix(mysql): collate identifier columns as utf8mb4_bin

* fix: add operator note to changelog

* fix: move tests to shared storage

* fix: separate migrations for each table

* fix: add runbook for migrations

* fix: set lock_wait_timeout

* fix: add docker instructions

* fix: add docker instructions

* fix: combine the migrations back into one, fix documentation for this

* fix: include details about table copy and

* Update CHANGELOG.md

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

---------

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: use constant-time comparison for preshared key authentication (openfga#3168)
chore(deps): bump the dependencies group with 2 updates (openfga#3166)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore(deps): bump the dependencies group with 2 updates (openfga#3167)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
release: update changelog for release `v1.17.1` (openfga#3165)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: bump grpc-health-probe to v0.4.52 (openfga#3164)

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
docs: update caching docs (openfga#3163)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: continuation token deserializer - handle `|` in type names (openfga#3152)
chore(deps): bump the dependencies group across 1 directory with 13 updates (openfga#3162)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#3156)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
fix: use query start time as iterator cache entry LastModified to prevent stale-read survival (openfga#3155)
chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.50 to v0.4.51 in the dependencies group (openfga#3157)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
chore: Bump go toolchain to 1.26.4 (openfga#3159)
fix: prevent v2Check from falling back for throttling and validation (openfga#3150)
ci: make pr benchmark comparisons less fragile (openfga#3153)

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
release: update changelog for release `v1.17.0` (openfga#3151)

Co-authored-by: Vic-Dev <vmichellej@gmail.com>
refactor: redesign cache key generation, making it more secure and consistent (openfga#3148)
feat: add configurable trace sampler with ParentBased support (openfga#3072)
release: update changelog for release `v1.16.1` (openfga#3147)
chore: update grpc-health-probe to latest to addres std lib CVEs (openfga#3146)
fix: skip v2Check weight2 pruning if iterator is unordered (openfga#3145)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore: add concurrency-group to PR-related CI steps (openfga#3140)
docs: move OIDC JWKS refresh entry from v1.15.1 to v1.16.0 (openfga#3142)
fix: when v2Check is primary algorithm, fix fallback condition and emit metrics (openfga#3141)
release: update changelog for release `v1.16.0` (openfga#3139)
Merge commit from fork

* fix: Standardize cache key generation everywhere

* Revert "fix: Standardize cache key generation everywhere"

This reverts commit ce60c6f9ae48a310a4dea2b824b5993520c8ba1c.

* length-encoded approach

* Revert "length-encoded approach"

This reverts commit b94637c187c57a2d3f3904247267bbc8ad21a41a.

* implement Hexer() and use in some cache keys

* appendConditionsHash -> generateConditionsHash

* mv Hexer -> BuildKey

* BuildKey -> BuildCacheKey

refactor to BuildCacheKey on each individual prefix component to remove collision risk

* make v2 cacheKey functions the standard

* make cache key prefixes consistent

* generateConditionsHash -> generateConditionsString

* delimit condition name string

* remove extra empty check

* relocate and reuse existing userTypeRestrictions function

* replace hashing of conditions for brevity

* fix tests

* cleanup, add test file

* remove unused slice capacity

* make prefix treatments consistent

* add nil-byte separator in object ids

* hash user type restrictions for brevity

* update comment string, use nil-byte separator for future-proofing

* remove call to xxhash.new

* adjustments for performance, consistency, and interface ergonomics.

* make condition hash generation more efficient.

* add clarifying comments for size caluculations

* fix builder growth calculations to match original intentions

* update outdated comment

* don't hash potentially zero values

* Revert "don't hash potentially zero values"

This reverts commit 2ad6c5b796bc20a82c1414c5146c3c708330eefa.

* add condition key separator unconditionally

* patch test expectations for new key structure

* export V2IteratorCachePrefix, use in tests

---------

Co-authored-by: justin <justin.cohen@okta.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
fix: unintentional zeroing of slice values by setting slice to nil (openfga#3135)
increase the check v2 trace information fidelity (openfga#3134)
feat: add datastore ping and ping retry configurations (openfga#3113)
fix: prevent v2Check strategies returning spurious false on context cancellation (openfga#3128)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix(authn/oidc): refresh JWKS on unknown kid to handle key rotation (openfga#3101)
fix: v2Check falls back to v1 on errors (openfga#3126)
fix: don't cache false results from cancelled-context goroutines in v2Check (openfga#3125)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
make union cache key unique by including the node input's label (openfga#3117)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
fix: shadow v2check and check use the same trace (openfga#3118)
fix: bump go toolchain version to 1.26.3 (openfga#3115)
chore: add more spans/attributes to v1 and v2 Check (openfga#3116)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: add matches attribute to shadowv2Check and Check spans (openfga#3114)
fix: use the same `request_id` for shadow traces in v2Check (openfga#3110)
release: update changelog for release `v1.15.1` (openfga#3112)
feat: reuse MySQL container across tests (openfga#3042)
fix: close all channels opened thus far, before return on error (openfga#3111)
chore: Add more spans/attributes to v2Check (openfga#3102)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: ensure acquired limiter token is released on throttle context cancelation (openfga#3106)
fix: cancel context before waiting on worker pool in ResolveUnionEdges (openfga#3105)
fix: replace golang.org/x/exp/maps with stdlib maps to resolve govet inline errors (openfga#3104)
fix: v2Check EdgeCacheKey collisions (openfga#3097)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
fix: expose context errors when they can be the potential cause of an underlying datastore error (openfga#3096)
chore(deps): bump the dependencies group across 1 directory with 2 updates (openfga#3093)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: move subproblem cache lookup from ResolveUnionEdges into ResolveUnion (openfga#3095)
chore(deps): bump the dependencies group with 4 updates (openfga#3092)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: error handler panic (openfga#3091)
release: update changelog for release `v1.15.0` (openfga#3090)
chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#3087)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: v2Check correctly uses query cache even when cache controller is disabled (openfga#3086)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3081)

Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump github.com/jackc/pgx/v5 from 5.9.1 to 5.9.2 (openfga#3085)

Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump grpc-ecosystem/grpc-health-probe from v0.4.47 to v0.4.48 in the dependencies group across 1 directory (openfga#3065)

Signed-off-by: dependabot[bot] <support@github.com>
feat: try to use UDS internally between HTTP server and gRPC server (openfga#2937)
feat: add jitter to internal cache TTLs to prevent thundering herd effects (openfga#3033)

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
list objects pipeline edge pruning (openfga#3075)
update toolchain go to 1.26.2 to address stdlib CVEs (openfga#3084)
chore: add store ID and datastore query/item count to shadowV2Check log (openfga#3073)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
CI speed up (openfga#3062)

Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Joshua Jones <joshua.jones@okta.com>
Add tracing to v2 Check planner strategy selection (openfga#3077)
fix: v2Check honours `check-query-cache-enabled` flag (openfga#3070)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
feat: reuse PostgreSQL container across tests (openfga#3018)
chore: fix reporter links in changelog (openfga#3069)
release: update changelog for release `v1.14.2` (openfga#3068)
fix: add null byte delimiter in contextual tuple cache keys and validation in v2Check (openfga#3064)
release: update changelog for release `v1.14.1` (openfga#3060)
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#3056)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: use a baseURL for AuthZEN configuration endpoint (openfga#3057)
chore: replace docker with moby (openfga#3047)
Iterator Cache V2: Storage Wrapper Pattern with Lock-Free Design (openfga#3016)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
test: fix flaky condition test (openfga#3058)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 6 updates (openfga#3045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.41.0 to 1.43.0 (openfga#3054)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
feat: add graceful shutdown timeout configuration (openfga#2976)
chore: update changelog to reflect playground off-by-default behavior (openfga#3053)
chore: decouple Error() and Unwrap() (openfga#3051)
perf: remove `fmt` from cache key generation (openfga#3006)
perf: enhancements for list objects (openfga#3043)
chore: remove stale notice file (openfga#3050)
docs: update 1.14.0 for CVE fix (openfga#3046)
feat: Add datastore throttling & concurrency limiting to v2Check (openfga#3035)

Signed-off-by: Saad Hussain <saad.hussain@okta.com>
release: update changelog for release `v1.14.0` (openfga#3040)
batch check cache (openfga#3025)
Merge commit from fork

Also prevent enabling playground when the server requires authentication
feat: add stats on tuple iterator query (openfga#3030)
fix: remove unnecessary non-deterministic test (openfga#3038)
remove unnecessary import (openfga#3032)
perf: improve the intersection algorithm, reducing latency and memory use (openfga#3031)
fix: ListObjects pipeline algorithm enhancements and fix for potential deadlock (openfga#3028)
chore: Also update openfga/helm-charts in release script (openfga#3010)
chore: update CICD to enforce GRPC healthprobe changes (openfga#2990)
fix: SQL `TupleOperation` serialization and `pgx.ErrNoRows` error handling (openfga#3014)
docs: update changelog for CVE-2026-33729 (openfga#3017)
chore: output the diff after running keep-a-changelog (openfga#3015)
chore(deps): bump the dependencies group across 1 directory with 11 updates (openfga#2998)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 10 updates (openfga#2999)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
release: update changelog for release `v1.13.1` (openfga#3002)
Merge commit from fork

* strip unicode control characters, encode context key length in cache key

* add cache_key tests to ensure we escape control characters and encode context key length

* run linter

* docs: update changelog

* Apply suggestion from @adriantam

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

* Apply suggestion from @adriantam

Co-authored-by: Adrian Tam <adrian.tam@okta.com>

---------

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
Co-authored-by: Saad Hussain <saad.h@outlook.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
release: update changelog for release `v1.13.0` (openfga#2997)
refactor: Separate caches for v1 and v2 Check (openfga#2968)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
docs: fix typos in comments (openfga#2972)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
observability: aggregate message statistics for each list-objects sender into a single span (openfga#2993)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
fix: capture panics in pipeline's base resolver, and return as errors. (openfga#2994)
docs: fix typos in RELEASES.md and Makefile (openfga#2980)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
AuthZen v1.0 Implementation (openfga#2875)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Rokibul Hasan <mdrokibulhasan@appscode.com>
Signed-off-by: Vihang Mehta <vihang@gimletlabs.ai>
Co-authored-by: Karl Persson <kalle.persson92@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Maria Ines Parnisari <maria.inesparnisari@okta.com>
Co-authored-by: Rokibul Hasan <mdrokibulhasan18@gmail.com>
Co-authored-by: José Padilla <jose.padilla@okta.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
Co-authored-by: Vihang Mehta <vihang@gimletlabs.ai>
Co-authored-by: Joshua Jones <joshua.jones.software@gmail.com>
Co-authored-by: Justin Cohen <justincoh@gmail.com>
release: update changelog for release `v1.12.1` (openfga#2992)
chore(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.3 (openfga#2988)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
chore: enforce minor version upgrade rule (openfga#2978)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
perf: tuple validation performance tweaks (openfga#2984)
fix: support URI schemes in OTLP endpoint configuration (openfga#2981)
refactor: remove custom pipes and replace with channels (openfga#2977)
chore(docs): added caching  docs (openfga#2664)

Co-authored-by: Saad Hussain <saad.hussain@okta.com>
release: update changelog for release `v1.12.0` (openfga#2974)
chore: update toolchain go to 1.26.1 (openfga#2975)
fix: update toolchain go to 1.25.8 to address stdlib CVEs (openfga#2971)
fix: correct swapped format args in DecodeParameterType error message (openfga#2961)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
perf: small tweaks to tuple validation functions (openfga#2963)

Co-authored-by: Vic-Dev <vmichellej@gmail.com>
test: add tests for condition parameter type any with complex context structures (openfga#2959)

Signed-off-by: Artem Muterko <artem@sopho.tech>
test: add functional test for ReadAssertions API endpoint (openfga#2960)

Signed-off-by: Artem Muterko <artem@sopho.tech>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
make configurable the maximum received grpc message size (openfga#2952)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
fix: set ExperimentalPipelineListObjects in experimentals by default (openfga#2957)

fix: `cache_item_count` metric overcounting (openfga#2950)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump the dependencies group across 1 directory with 7 updates (openfga#2953)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
refactor: Make shadowV2Check final log clearer (openfga#2946)

Move telemetry package to internal/telemetry (openfga#2938)

Signed-off-by: Oleksandr Shestopal <ar.shestopal-oshegithub@gmail.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
chore(deps): bump the dependencies group across 1 directory with 3 updates (openfga#2956)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: Resolve race condition in check reducers (openfga#2947)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
fix: gateway grpc client tls cert rotation (openfga#2951)

Signed-off-by: Shashank Goel <goelshashank13@gmail.com>
fix: disable LO pipeline if ff has it set for a store (openfga#2945)

chore(deps): bump the dependencies group across 1 directory with 4 updates (openfga#2949)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fix: various random fixes (openfga#2942)

refactor: check using weighted graph (openfga#2816)

Co-authored-by: Yissell Garma <yissell.garma@okta.com>
release: update changelog for release `v1.11.6` (openfga#2939)

feat: enable pipeline algorithm by default (openfga#2921)

add tests to exercise reported bug (openfga#2934)

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Adrian Tam <adrian.tam@okta.com>
refine AGENTS.md to make it more concise with higher value. (openfga#2936)

Co-authored-by: Justin Cohen <justincoh@gmail.com>
migrate grpc dial context to NewClient (openfga#2714)

Co-authored-by: Adrian Tam <adrian.tam@okta.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
chore(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (openfga#2935)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.