oscerd commented on PR #26974:
URL: https://github.com/apache/camel/pull/26974#issuecomment-5907587095

   All four applied. Two of them were not only wording, so thanks for pushing 
on them.
   
   **`reject()`** — `validated()` serves three call sites: the configured 
triple and both body paths. So a tuple from the message body with a blank part 
was told that "a configured tuple is never completed from the message body", 
sending the reader to configuration that was not involved at all. The message 
now names the source it actually came from, and a test pins the body wording 
and asserts it does *not* mention configuration.
   
   **The failOpen-but-denied warning** — you are right, and my own allowlist 
change is what made it wrong. It claimed OpenFGA had rejected the request, 
which is now false for most of what it covers: an interrupt, a request the SDK 
refused to build, and input that could not be serialised never reach OpenFGA. 
It now says the failure is not an unreachable decision point, without 
attributing a rejection to the server.
   
   **The adoc paragraph** — confirmed, and it was my edit that caused it: the 
allowlist text got prepended onto the existing sentence, so "The query 
operations ignore it entirely" trailed a paragraph about unfamiliar failures. 
It is now its own paragraph naming `failOpen` explicitly.
   
   **The interrupt test** — a fair catch, and the same shape as the thing this 
method kept getting wrong. `Thread.interrupted()` was being called only to 
clear the flag, with the result thrown away, so nothing verified the component 
had restored it. The result is captured and asserted now.
   
   I also dropped `public` from `OpenFgaIT`, per the convention that new test 
classes are package-private; it still runs its twelve tests without it.
   
   One generated change to expect in the diff: `SecurityUtils` records which 
components own each insecure option, and `failopen` is now owned by 
`component:opa` and `component:openfga`, so that set literal gains a second 
entry. `component:opa` keeps its ownership — the `-` line is only the literal 
reflowing.
   
   98 unit tests and 12 ITs pass; rebased on current `main`, full reactor clean.
   
   ---
   
   _Claude Code on behalf of @oscerd_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to