davsclaus commented on code in PR #27185:
URL: https://github.com/apache/camel/pull/27185#discussion_r4155221399


##########
components/camel-openfga/src/main/docs/openfga-component.adoc:
##########
@@ -320,11 +320,51 @@ No check is registered for an injected `openFgaClient`, 
which can point anywhere
 about. Set `healthCheckProducerEnabled=false` on the component, or 
`healthCheckEnabled=false` on the policy, to
 turn them off.
 
+=== Contextual tuples and condition context
+
+`contextualTuples` hands OpenFGA relationships that are true for one request 
and never stored — a group membership
+that lives in the token rather than in the graph, or a fact about the request 
such as which network it arrived on.
+It takes semicolon-separated `user,relation,object` triples, each part a 
Simple expression:
+
+[source,java]
+------------------------------------------------------------
+to("openfga:check?storeId={{fga.store}}&relation=reader"
+   + "&user=user:${exchangeProperty.CamelKeycloakTokenSubject}"
+   + "&object=document:${header.documentId}"
+   + 
"&contextualTuples=user:${exchangeProperty.CamelKeycloakTokenSubject},member,team:${header.team}");

Review Comment:
   `team:${header.team}` makes a caller-supplied header part of a tuple that 
*grants*. If `team` arrives with the request, the caller chooses its own team 
membership for this check, which is the case the IMPORTANT block below warns 
about. Could the example take the team from something the route established (a 
token claim on an exchange property, or a literal), so the example follows the 
doc's own rule? The PR description has the same example.



##########
components/camel-openfga/src/test/java/org/apache/camel/component/openfga/OpenFgaContextualTuplesTest.java:
##########
@@ -0,0 +1,194 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.openfga;
+
+import java.util.List;
+import java.util.Map;
+import java.util.concurrent.CompletableFuture;
+
+import dev.openfga.sdk.api.client.OpenFgaClient;
+import dev.openfga.sdk.api.client.model.ClientCheckRequest;
+import dev.openfga.sdk.api.client.model.ClientCheckResponse;
+import dev.openfga.sdk.api.client.model.ClientListObjectsResponse;
+import dev.openfga.sdk.api.client.model.ClientTupleKey;
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.Exchange;
+import org.apache.camel.test.junit6.CamelTestSupport;
+import org.junit.jupiter.api.Test;
+import org.mockito.ArgumentCaptor;
+
+import static org.assertj.core.api.Assertions.assertThat;
+import static org.assertj.core.api.Assertions.assertThatThrownBy;
+import static org.mockito.ArgumentMatchers.any;
+import static org.mockito.Mockito.mock;
+import static org.mockito.Mockito.never;
+import static org.mockito.Mockito.verify;
+import static org.mockito.Mockito.when;
+
+class OpenFgaContextualTuplesTest extends CamelTestSupport {
+
+    private static final String STORE = "01HQMVAJXYZ0000000000000";
+    private static final String BASE = "?openFgaClient=#fgaClient&storeId=" + 
STORE;
+
+    @BindToRegistry("fgaClient")
+    private final OpenFgaClient client = mock(OpenFgaClient.class);
+
+    @BindToRegistry("myContext")
+    private final Map<String, Object> conditionContext = Map.of("hour", 14, 
"onCorpNetwork", true);
+
+    private void givenVerdict(Boolean allowed) throws Exception {
+        ClientCheckResponse response = mock(ClientCheckResponse.class);
+        when(response.getAllowed()).thenReturn(allowed);
+        when(client.check(any(ClientCheckRequest.class), 
any())).thenReturn(CompletableFuture.completedFuture(response));
+    }
+
+    private ClientCheckRequest captureCheck() throws Exception {
+        ArgumentCaptor<ClientCheckRequest> captor = 
ArgumentCaptor.forClass(ClientCheckRequest.class);
+        verify(client).check(captor.capture(), any());
+        return captor.getValue();
+    }
+
+    @Test
+    void sendsTheConfiguredContextualTuplesWithTheCheck() throws Exception {
+        givenVerdict(Boolean.TRUE);
+
+        Exchange out = template.request(
+                "openfga:check" + BASE + 
"&relation=reader&user=user:anne&object=document:budget"
+                                        + 
"&contextualTuples=user:anne,member,team:eng;user:anne,on_network,network:corp",
+                e -> {
+                });
+
+        assertThat(out.getException()).isNull();
+        assertThat(captureCheck().getContextualTuples())
+                .extracting(ClientTupleKey::getUser, 
ClientTupleKey::getRelation, ClientTupleKey::getObject)
+                .containsExactly(
+                        org.assertj.core.groups.Tuple.tuple("user:anne", 
"member", "team:eng"),

Review Comment:
   Nit: no name clash here, so `import static 
org.assertj.core.groups.Tuple.tuple;` (and an import for 
`ClientListObjectsRequest` further down) instead of FQCNs, per the project's 
import-style rule.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to