oscerd commented on PR #26974:
URL: https://github.com/apache/camel/pull/26974#issuecomment-5888679526

   One further narrowing on the same method, prompted by a note from the 
camel-opa work about `UncheckedIOException` wrappers.
   
   `isDecisionPointUnavailable` returned on the **first** `IOException` in the 
cause chain, so a disqualifying cause underneath a transport-looking layer was 
never reached. `IOException("connection reset", cause: 
SdkSerializationException)` therefore failed open, even though the request had 
never been formed. Reverting to the first-match behaviour fails the new test, 
so this was live rather than theoretical.
   
   The walk now finishes before concluding anything:
   
   - an `FgaError` decides outright, since an HTTP status is the most specific 
evidence available;
   - `SdkSerializationException` and `InterruptedException` disqualify the 
failure **wherever** they sit in the chain — either can be wrapped by something 
that looks like a transport failure, and `SdkSerializationException` extends 
`IOException` to begin with;
   - a transport-looking layer is noted and the walk continues;
   - the default is still a denial.
   
   97 unit tests and 12 ITs pass, rebased on current `main`, full reactor clean.
   
   For the record, since it bears on how much weight to put on this file: the 
fail-open boundary in this component has now yielded four distinct real leaks, 
each confirmed by reverting the fix and watching the test fail rather than by 
inspection —
   
   1. HTTP 4xx treated as unavailability (found in review here);
   2. a pre-flight `FgaInvalidParameterException`, where nothing was ever asked;
   3. `SdkSerializationException` passing for a transport failure;
   4. a disqualifying cause hidden under a transport-looking wrapper.
   
   The interrupt path was already correct, but the only thing asserting so was 
a comment, so it has a test now too. 
`OpenFgaAuthorizer.isDecisionPointUnavailable` and 
`OpenFgaProducer.resolveTuples` are where the defects clustered, and they are 
the two places I would most value a human read on.
   
   ---
   
   _Claude Code on behalf of @oscerd_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to