v4.13.0
Release 4.13.0, available on crates.io
Changed
- *A
hasexpression with a chain of attributes (e has a.b.c) now converts to JSON as a
singlehasnode whoseattrfield is an array (["a", "b", "c"]), instead of a
conjunction of one-attributehaschecks ((e has a) && (e.a has b) && (e.a.b has c)).
A single-attributehasstill converts withattras a string. The evaluation result is
unchanged (#2560). - Invalid action application errors ("Unable to find an applicable action given the policy scope constraints")
are now reported as validation warnings instead of errors. These do not indicate that a run-time
error may exist in the policy. They are similar to the impossible policy warning, indicating that a policy
cannot apply to any request. This change makes it possible to remove entries from anappliesTolist
without introducing validation errors. Callers that want to keep rejecting these policies should check
ValidationResult::validation_warningsforValidationWarning::InvalidActionApplication(#2545). - For the
tpeexperimental feature,is_authorized_batchednow automatically loads actions
entities from the schema, and will now return immediately on reaching a concrete authorization decision (#2554). - For the
tpeexperimental feature, removed theBatchedEvalError::MissingEntitieserror variant
which was never constructed (#2554). - For the
tpeexperimental feature,PolicySet::tpeis faster on large policy sets
(~1.4x on a 25,000-policy set) (#2558).
Fixed
- Fixed
Policy::try_into_pst()andTemplate::try_into_pst()to preserve policy IDs for text- and JSON-backed values, restoringPolicySet::try_into_pst()/PolicySet::from_pst()round trips (#2543). - In the experimental
protobufsfeature, theSchema::decodefunction now accepts schemas that referenceActionentity types not defined in the schema. This was previously rejected (#2491). - For the experimental
tpefeature, fixedTpeResponse::policy_setto return the residual policies, matchingTpeResponse::policiesas documented. Previously it returned the original policies (#2540). - For the experimental
tpefeature, partial entity validation now accept action entities with unknown components. TheUnknownActionComponentis now never returned and is deleted (#2555).