Repository navigation
Dynamic Entity joins and updates - #2930
Merged
Merged
Conversation
direction inferred from which entity holds the reference field (forward: the record's field names the other record; reverse: the other records' field names this one; direction required only for a self-reference), cardinality at_most_one / many / exists, where filters in the obp_filter grammar, pick latest_by / earliest_by. Same read rules as a GET: shared records only, row-level access list, read-restricted fields null.
space only (its bank id, or SYS and the empty bank id for the system space), not every bank's grants of those Role names; the Roles stay registered while an entity of that name is left in another space. Test: DynamicEntityDeleteEntitlementsTest + Dynamic Query security and audit: obp_exists onto a row-level entity counts only rows the caller may read (the caller is passed to the projection, and with no caller it fails closed) + every Dynamic Resource Doc call records an API Metric, refused or answered + OBP-40066 names every Dynamic Entity the caller may not read, with its Role and bank + v7.0.0 POST /management/dynamic-resource-docs/explain: the reads a Dynamic Query would make, with their SQL (values as ?), and the access it needs, for the caller or an anonymous caller + hide_field_from_public_access on Dynamic Entity fields + OBP-09025: no filtering or sorting Dynamic Entity records by a field the caller may not read (public, authenticated, community and row-level GET) + DynamicQueryAccessTest: four Dynamic Entities joined, public and not + Bank level resource docs: GET /banks/BANK_ID/resource-docs/API_VERSION/obp checked the bank exists, then listed every space's dynamic docs because the handler passed no bank id to the filter. It now lists that space only, and BANK_ID may be SYS for the system space (docs that belong to no bank). Dynamic Resource Docs now record their bank in createdByBankId, so they appear at their own bank too. New routes /banks/BANK_ID/resource-docs/API_VERSION/openapi and openapi.yaml serve the same docs as OpenAPI 3.1, with a ResourceDoc and the documentation rate limit scope. The content=dynamic swagger, openapi and openapi.yaml documents move from the static swagger cache to the dynamic resource docs cache, which Dynamic Entity changes already clear, so a new Dynamic Entity no longer stays missing for the cache TTL. Creating, updating or deleting a Dynamic Endpoint or Dynamic Resource Doc now clears it too.
optional properties (the stored records simply don't have them); every existing property must still keep its name and type, and required may not grow, so adding a required property, removing one or changing a type is still refused with OBP-09023. OBP-09023 text and the v4.0.0 Update System / Bank Level / My Dynamic Entity descriptions say so. Tests: SchemaCompatibleChangeSpec (optional added accepted, required added refused, removed refused) and DynamicEntityTest (an optional property added over HTTP is accepted and the record kept; a required one is refused)
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



No description provided.