Skip to content

fix(apply): match type-prefix objects in scopeDesired - #21

Merged
ewanharris merged 2 commits into
mainfrom
fix/apply-scope-desired-prefix
Oct 9, 2026
Merged

ewanharris merged 2 commits into
mainfrom
fix/apply-scope-desired-prefix

Conversation

@ewanharris

@ewanharris ewanharris commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Description

What problem is being solved?

scopeDesired compared t.Object != filter.Object exactly. A patch filter with a type-prefix object (e.g. "org:") never matched any desired tuple because "org:acme" does not equal "org:". This left the scoped set empty, which diffFilter treated as "delete everything the filter read" — a silent mass delete of every matching tuple.

From v0.1.0 the new coverage check in validate turns this into a hard error before any I/O, so the mapping can never process a matching event rather than mass-deleting. Failing closed is better, but the rule shape still can't work.

How is it being solved?

Detect type-prefix objects (non-empty string ending in ":") and use strings.HasPrefix instead of equality, matching how FGA Read interprets the same filter and how isTupleCoveredByFilter in mapping.go already behaves. isObjectTypePrefix is duplicated from mapping.go following the existing pattern in that file.

What changes are made to solve it?

scopeDesired in apply/apply.go gains a prefix branch for the object field. isObjectTypePrefix is added to the same file. Three new table-driven test cases in TestScopeDesired cover: prefix matches all objects of that type, prefix with a relation filter, and prefix that matches no objects (different type).

Changelog

BEGIN_COMMIT_OVERRIDE
fix(apply): patch filters with type-prefix objects (e.g. org:) now correctly scope desired tuples by prefix match rather than exact equality, consistent with how FGA Read interprets the same filter; previously this caused a silent mass delete of all matching tuples, or from v0.1.0 a hard coverage error on every matching event
END_COMMIT_OVERRIDE

References

Review Checklist

  • I have clicked on "allow edits by maintainers".
  • I have added documentation for new/changed functionality in this PR or in a PR to openfga.dev [Provide a link to any relevant PRs in the references section above]
  • The correct base branch is being used, if not main
  • I have added tests to validate that the change in functionality is working as expected

A filter with an object like "org:" is a type prefix: FGA Read returns
every org:* tuple for it. scopeDesired was comparing exact equality, so
"org:acme" never matched "org:" and the scoped set was always empty.

Fix by detecting type-prefix objects (non-empty string ending in ":") and
using strings.HasPrefix instead of equality, matching how FGA Read and
isTupleCoveredByFilter already behave. isObjectTypePrefix is duplicated
from mapping.go following the existing pattern in that file.
@ewanharris
ewanharris requested a review from a team as a code owner October 9, 2026 10:27
Copilot AI balanced review requested due to automatic review settings October 9, 2026 10:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches existing filter semantics and includes focused tests; only a minor stale comment remains.

1 open finding
What changed in this PR

Fixes desired tuple scoping for object type-prefix filters, preventing erroneous empty scopes.

Changes:

  • Adds prefix-aware object matching.
  • Adds coverage for prefix and relation combinations.
File Description
apply/​apply.go Implements type-prefix matching.
apply/​apply_test.go Tests prefix-filter behavior.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apply/apply.go
@ewanharris
ewanharris enabled auto-merge (squash) October 9, 2026 10:38
@ewanharris
ewanharris merged commit 043802d into main Oct 9, 2026
20 checks passed
@ewanharris
ewanharris deleted the fix/apply-scope-desired-prefix branch October 9, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants