fix(xtest): match URI-scoped private key cache hits - #615
Conversation
Signed-off-by: Chris Reed <creed@virtru.com>
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe ABAC test now matches cached private-key audit entries by the full cache key JSON, using the KAS URI and key ID. ChangesABAC cache assertion
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Other Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the cache at night Comment |
|
Rebased onto main after #606, #612 and #615 landed; findings those PRs already addressed are dropped, including the km3 action pin, which #612 synchronized with its siblings. - Skip the km3 tests when no km3 is listening, instead of failing with connection-refused inside an SDK CLI. The feature gate answers "is the override set?", not "does a km3 exist?". (A later commit in this stack turns that skip into a failure.) - Add kas-km3 (8787) to otdf-local, with the kas_uri_from_kao setting, the 5-minute key cache and debug logging its CI step uses, so all three km3 tests are runnable locally. - Document that kas_uri_from_kao is forced via XT_FORCE_PLATFORM_SUPPORTS (not XT_FORCE_SUPPORTS) and that km3 starts on the PR gate and nightlies while every test behind the gate skips.
Rebased onto main after #606, #612 and #615 landed; findings those PRs already addressed are dropped, including the km3 action pin, which #612 synchronized with its siblings. - Skip the km3 tests when no km3 is listening, instead of failing with connection-refused inside an SDK CLI. The feature gate answers "is the override set?", not "does a km3 exist?". (A later commit in this stack turns that skip into a failure.) - Add kas-km3 (8787) to otdf-local, with the kas_uri_from_kao setting, the 5-minute key cache and debug logging its CI step uses, so all three km3 tests are runnable locally. - Document that kas_uri_from_kao is forced via XT_FORCE_PLATFORM_SUPPORTS (not XT_FORCE_SUPPORTS) and that km3 starts on the PR gate and nightlies while every test behind the gate skips.



The cache isolation test still expects registry IDs in cache-hit logs, so it fails after opentdf/platform#4056 changes cache identity to quoted KAS URI + key ID. Match the complete
cache_keyvalue so/kascannot also satisfy the shorter URI’s assertion.Validation: Ruff lint/format and Pyright passed; checked matching against both URIs and rejection of wrong IDs, registry IDs, and the old prefix. Cross-SDK validation is running against platform commit
110f84d3263c0479ca598c793074a1543cb9bc20, with KAO/cache coverage enabled.Summary by CodeRabbit