oscerd commented on PR #26974:
URL: https://github.com/apache/camel/pull/26974#issuecomment-5888679526
One further narrowing on the same method, prompted by a note from the
camel-opa work about `UncheckedIOException` wrappers.
`isDecisionPointUnavailable` returned on the **first** `IOException` in the
cause chain, so a disqualifying cause underneath a transport-looking layer was
never reached. `IOException("connection reset", cause:
SdkSerializationException)` therefore failed open, even though the request had
never been formed. Reverting to the first-match behaviour fails the new test,
so this was live rather than theoretical.
The walk now finishes before concluding anything:
- an `FgaError` decides outright, since an HTTP status is the most specific
evidence available;
- `SdkSerializationException` and `InterruptedException` disqualify the
failure **wherever** they sit in the chain — either can be wrapped by something
that looks like a transport failure, and `SdkSerializationException` extends
`IOException` to begin with;
- a transport-looking layer is noted and the walk continues;
- the default is still a denial.
97 unit tests and 12 ITs pass, rebased on current `main`, full reactor clean.
For the record, since it bears on how much weight to put on this file: the
fail-open boundary in this component has now yielded four distinct real leaks,
each confirmed by reverting the fix and watching the test fail rather than by
inspection —
1. HTTP 4xx treated as unavailability (found in review here);
2. a pre-flight `FgaInvalidParameterException`, where nothing was ever asked;
3. `SdkSerializationException` passing for a transport failure;
4. a disqualifying cause hidden under a transport-looking wrapper.
The interrupt path was already correct, but the only thing asserting so was
a comment, so it has a test now too.
`OpenFgaAuthorizer.isDecisionPointUnavailable` and
`OpenFgaProducer.resolveTuples` are where the defects clustered, and they are
the two places I would most value a human read on.
---
_Claude Code on behalf of @oscerd_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]