Repository navigation
fix(apply): match type-prefix objects in scopeDesired - #21
Merged
Merged
Conversation
A filter with an object like "org:" is a type prefix: FGA Read returns every org:* tuple for it. scopeDesired was comparing exact equality, so "org:acme" never matched "org:" and the scoped set was always empty. Fix by detecting type-prefix objects (non-empty string ending in ":") and using strings.HasPrefix instead of equality, matching how FGA Read and isTupleCoveredByFilter already behave. isObjectTypePrefix is duplicated from mapping.go following the existing pattern in that file.
There was a problem hiding this comment.
🟢 Approval recommended
The implementation matches existing filter semantics and includes focused tests; only a minor stale comment remains.
1 open finding
What changed in this PR
Fixes desired tuple scoping for object type-prefix filters, preventing erroneous empty scopes.
Changes:
- Adds prefix-aware object matching.
- Adds coverage for prefix and relation combinations.
| File | Description |
|---|---|
apply/apply.go |
Implements type-prefix matching. |
apply/apply_test.go |
Tests prefix-filter behavior. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
ewanharris
enabled auto-merge (squash)
October 9, 2026 10:38
sergiught
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
What problem is being solved?
scopeDesiredcomparedt.Object != filter.Objectexactly. A patch filter with a type-prefix object (e.g."org:") never matched any desired tuple because"org:acme"does not equal"org:". This left the scoped set empty, whichdiffFiltertreated as "delete everything the filter read" — a silent mass delete of every matching tuple.From v0.1.0 the new coverage check in
validateturns this into a hard error before any I/O, so the mapping can never process a matching event rather than mass-deleting. Failing closed is better, but the rule shape still can't work.How is it being solved?
Detect type-prefix objects (non-empty string ending in
":") and usestrings.HasPrefixinstead of equality, matching how FGA Read interprets the same filter and howisTupleCoveredByFilterinmapping.goalready behaves.isObjectTypePrefixis duplicated frommapping.gofollowing the existing pattern in that file.What changes are made to solve it?
scopeDesiredinapply/apply.gogains a prefix branch for the object field.isObjectTypePrefixis added to the same file. Three new table-driven test cases inTestScopeDesiredcover: prefix matches all objects of that type, prefix with a relation filter, and prefix that matches no objects (different type).Changelog
BEGIN_COMMIT_OVERRIDE
fix(apply): patch filters with type-prefix objects (e.g.
org:) now correctly scope desired tuples by prefix match rather than exact equality, consistent with how FGA Read interprets the same filter; previously this caused a silent mass delete of all matching tuples, or from v0.1.0 a hard coverage error on every matching eventEND_COMMIT_OVERRIDE
References
Review Checklist
main