Skip to content

1.0.0-beta7

Latest

Choose a tag to compare

@hexblot hexblot released this 05 Oct 09:58
Immutable release. Only release title and notes can be modified.
1.0.0-beta7
fc5d397

Added

  • Model\GraphValidator: one validator for a whole logistics-object or
    event graph, root and every embedded node, used by ChangeApplier,
    POST /logistics-objects and the logistics-events endpoints alike, so no
    ingestion path accepts what another refuses (adversarial review 10).

Fixed

  • A change could introduce an embedded node of an unknown class, which then
    escaped validation along with any property attached to it; a node of a
    logistics object class; or a node of the wrong class for the property.
    ChangeApplier refuses the class up front and the validator judges the
    rest (R10-001, R10-002).
  • Comparer normalised only five of the twelve XSD integer types, so a
    delete spelled as xsd:byte did not match a stored xsd:integer and an
    add of the same number was not a duplicate; it now takes the integer
    family from Rdf\Xsd (R10-003).
  • POST /logistics-objects validated the root's properties only; embedded
    nodes, property kinds and ranges are now validated (R10-004). Posted
    events are validated the same way, embedded locations included (D10-001).
    One exception stays deliberate: a nested logistics object in a POST body
    (the spec's own example A2) is still accepted and kept embedded, since
    splitting it into an object of its own is not implemented (spec question
    33); a change or an event may not introduce one.
  • An xsd:date offset is bounded to 14:00 like a dateTime's (D10-002).
  • An embedded node a client identified itself (an https: or urn: id,
    NE:ONE's neone: scheme) escaped validation on creation and on posted
    events, could not be addressed by a change afterwards and was never
    cleansed when unlinked. Every non-root subject of a graph is now an
    embedded node: the validator judges it, withEmbeddedIds() gives it a
    server-minted internal: id when the object is stored, and the change
    applier addresses and cleanses it whatever id it carries (adversarial
    review 11).
  • A typed link, a reference that states the class of what it points to and
    nothing else, escaped validation when its class was unknown to the
    ontology (R12-001), and an unrelated change removed its class as an
    orphan (R12-002). Its class must now exist, as a class of the data model
    or as a code list, and whatever a reachable node links to is kept. A
    type-only node with an id of its own is a reference by design, not an
    embedded node: a change cannot describe it in place, and the guide says
    how to embed instead (R12-003).
  • A code list did not count as a class when a property's range was checked,
    so a unit typed with the wrong list, or a code list where a class was
    expected, passed (R13-001). It counts now, and an untyped member IRI of
    the wrong list is caught by its IRI when the property expects a list.
  • A nested logistics object that creation had accepted (spec question 33)
    made every later change to the object fail, since the change applier
    judged the finished graph without that allowance (R14-001). It is allowed
    there now; a change still cannot introduce one, and the type of any node,
    embedded nodes included, can no longer be changed through a change.
  • A language-tagged literal skipped the datatype range check, so "many"@en
    entered an integer property (R14-002). Tagged text now fits a string range
    and nothing else.
  • The bulk event route dropped a malformed cargo:eventFor value and
    reported no failure (R14-003); it answers 400 like the single-object route.
  • A non-string or empty @id on creation was treated as absent and a URI
    with a space became a 500 (R14-004); every malformed @id is a 400.
  • JwksKeyResolver ignored key_ops; a key published for encryption only
    could verify tokens (D14-001). A present key_ops must include verify,
    and the selection policy is in the guide. A key_ops, use or alg
    member that is present but malformed, null included, now fails closed
    as the guide says, and a skipped key is logged with its reason (R15-001,
    D15-001).