Skip to content

Dynamic Entity joins and updates - #2930

Merged
simonredfern merged 4 commits into
OpenBankProject:developfrom
simonredfern:develop
Oct 2, 2026
Merged

simonredfern merged 4 commits into
OpenBankProject:developfrom
simonredfern:develop

Conversation

@simonredfern

Copy link
Copy Markdown
Member

No description provided.

direction inferred from which entity holds the reference field (forward:
the record's field names the other record; reverse: the other records'
field names this one; direction required  only for a self-reference),
cardinality at_most_one / many / exists, where filters in the obp_filter
grammar, pick latest_by / earliest_by. Same read rules as a GET: shared
records only, row-level access list, read-restricted fields null.
space only (its bank id, or SYS and the empty bank id for the system
space), not every bank's grants of those Role names; the Roles stay
registered while an entity of that name is left in another space. Test:
DynamicEntityDeleteEntitlementsTest + Dynamic Query security and audit:
obp_exists onto a row-level entity counts only rows the caller may read
(the caller is passed to the projection, and with no caller it fails
closed) + every Dynamic Resource Doc call records an API Metric, refused
or answered + OBP-40066 names every Dynamic Entity the caller may not
read, with its Role and bank + v7.0.0 POST
/management/dynamic-resource-docs/explain: the reads a Dynamic Query
would make, with their SQL (values as ?), and the access it needs, for
the caller or an anonymous caller + hide_field_from_public_access on
Dynamic Entity
fields + OBP-09025: no filtering or sorting Dynamic Entity records by a
field the caller may not read (public, authenticated,
community and row-level GET) + DynamicQueryAccessTest: four Dynamic
Entities joined, public and not + Bank level resource docs: GET
/banks/BANK_ID/resource-docs/API_VERSION/obp checked the bank exists,
then listed every space's dynamic docs because the handler
passed no bank id to the filter. It now lists that space only, and
BANK_ID may be SYS for the system space (docs that belong to no
bank). Dynamic Resource Docs now record their bank in createdByBankId,
so they appear at their own bank too. New routes
/banks/BANK_ID/resource-docs/API_VERSION/openapi and openapi.yaml serve
the same docs as OpenAPI 3.1, with a ResourceDoc and the
documentation rate limit scope. The content=dynamic swagger, openapi and
openapi.yaml documents move from the static swagger cache
to the dynamic resource docs cache, which Dynamic Entity changes already
clear, so a new Dynamic Entity no longer stays missing for
the cache TTL. Creating, updating or deleting a Dynamic Endpoint or
Dynamic Resource Doc now clears it too.
optional properties (the stored records simply don't have them); every
existing property must still keep its name and type, and required may
not grow, so adding a required property, removing one  or changing a
type is still refused with OBP-09023. OBP-09023 text and the v4.0.0
Update System / Bank Level / My Dynamic Entity
descriptions say so. Tests: SchemaCompatibleChangeSpec (optional added
accepted, required added refused, removed refused) and DynamicEntityTest
(an optional property added over HTTP is accepted and the record kept; a
required one is refused)
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@simonredfern
simonredfern merged commit 59351d2 into OpenBankProject:develop Oct 2, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant