Skip to content

feat(policy)!: add namespace field to Actions proto - #3130

Merged
elizabethhealy merged 6 commits into
mainfrom
dspx-2540-action-protos-namespaced
Mar 12, 2026
Merged

feat(policy)!: add namespace field to Actions proto#3130
elizabethhealy merged 6 commits into
mainfrom
dspx-2540-action-protos-namespaced

Conversation

@elizabethhealy

@elizabethhealy elizabethhealy commented Mar 10, 2026

Copy link
Copy Markdown
Member

Proposed Changes

This pull request introduces namespace support to the policy service, primarily focusing on Actions. It adds a namespace field to the Action protobuf definition and integrates namespace_id and namespace_fqn fields into request messages for creating, retrieving, and listing actions. These new fields are accompanied by robust validation rules to ensure data consistency and proper identification of namespaces. The changes also include updates to the gRPC documentation and expanded unit tests to cover the new validation logic.

Highlights

  • Namespace Field Added to Action Proto: A new namespace field of type Namespace has been introduced to the policy.Action message in service/policy/objects.proto, providing a namespace context for actions.
  • Namespace Identifiers in Action Request Messages: GetActionRequest, ListActionsRequest, and CreateActionRequest in service/policy/actions/actions.proto now include namespace_id (UUID) and namespace_fqn (URI) fields, which are required and mutually exclusive (oneof).
  • Validation for Namespace Fields: Comprehensive validation rules have been added for the new namespace_id and namespace_fqn fields, ensuring they adhere to UUID and URI formats respectively, and that one of them is always provided.

Checklist

  • I have added or updated unit tests
  • I have added or updated integration tests (if appropriate)
  • I have added or updated documentation

Testing Instructions

@github-actions github-actions Bot added comp:policy Policy Configuration ( attributes, subject mappings, resource mappings, kas registry) docs Documentation size/s labels Mar 10, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces namespace support to the policy service, primarily focusing on Actions. It adds a namespace field to the Action protobuf definition and integrates namespace_id and namespace_fqn fields into request messages for creating, retrieving, and listing actions. These new fields are accompanied by robust validation rules to ensure data consistency and proper identification of namespaces. The changes also include updates to the gRPC documentation and expanded unit tests to cover the new validation logic.

Highlights

  • Namespace Field Added to Action Proto: A new namespace field of type Namespace has been introduced to the policy.Action message in service/policy/objects.proto, providing a namespace context for actions.
  • Namespace Identifiers in Action Request Messages: GetActionRequest, ListActionsRequest, and CreateActionRequest in service/policy/actions/actions.proto now include namespace_id (UUID) and namespace_fqn (URI) fields, which are required and mutually exclusive (oneof).
  • Validation for Namespace Fields: Comprehensive validation rules have been added for the new namespace_id and namespace_fqn fields, ensuring they adhere to UUID and URI formats respectively, and that one of them is always provided.
  • Updated Documentation: The gRPC documentation (docs/grpc/index.html) has been updated to reflect the addition of the namespace field to Action and RegisteredResource messages, and the namespace_id/namespace_fqn fields to various action and registered resource request messages.
  • Expanded Unit Tests: Unit tests in service/policy/actions/actions_test.go have been extended to cover the validation logic for the new namespace fields in CreateActionRequest, GetActionRequest, and ListActionsRequest.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Changelog
  • docs/grpc/index.html
    • Added documentation for the namespace field to the policy.Action message.
    • Added documentation for the namespace field to the policy.RegisteredResource message.
    • Added documentation for namespace_id and namespace_fqn fields to policy.actions.CreateActionRequest.
    • Added documentation for namespace_id and namespace_fqn fields to policy.actions.GetActionRequest.
    • Added documentation for namespace_id and namespace_fqn fields to policy.actions.ListActionsRequest.
    • Added documentation for namespace_id and namespace_fqn fields to policy.registeredresources.CreateRegisteredResourceRequest.
    • Added documentation for namespace_fqn field to policy.registeredresources.GetRegisteredResourceRequest.
    • Added documentation for namespace_id and namespace_fqn fields to policy.registeredresources.ListRegisteredResourcesRequest.
  • service/policy/actions/actions.proto
    • Added namespace_id and namespace_fqn fields to GetActionRequest, with a oneof constraint and validation rules for UUID and URI formats.
    • Added namespace_id and namespace_fqn fields to ListActionsRequest, with a oneof constraint and validation rules.
    • Added namespace_id and namespace_fqn fields to CreateActionRequest, with a oneof constraint and validation rules.
  • service/policy/actions/actions_test.go
    • Added validNamespaceFQN constant.
    • Added errMessageOneof constant.
    • Updated Test_CreateActionRequest_Fails to include tests for missing namespace, invalid namespace ID, and invalid namespace FQN.
    • Updated Test_CreateActionRequest_Succeeds to include NamespaceId or NamespaceFqn in successful requests.
    • Updated Test_GetAction_Succeeds to include NamespaceId or NamespaceFqn in successful requests.
    • Updated Test_GetAction_Fails to include tests for missing namespace, invalid namespace ID, and invalid namespace FQN.
    • Added Test_ListActions_Fails to test for missing namespace, invalid namespace ID, and invalid namespace FQN.
    • Updated Test_ListActions_Succeeds to include NamespaceId or NamespaceFqn in successful requests.
  • service/policy/objects.proto
    • Added a namespace field of type Namespace to the Action message.
Ignored Files
  • Ignored by pattern: docs/openapi/**/* (10)
    • docs/openapi/authorization/authorization.openapi.yaml
    • docs/openapi/authorization/v2/authorization.openapi.yaml
    • docs/openapi/policy/actions/actions.openapi.yaml
    • docs/openapi/policy/attributes/attributes.openapi.yaml
    • docs/openapi/policy/objects.openapi.yaml
    • docs/openapi/policy/obligations/obligations.openapi.yaml
    • docs/openapi/policy/registeredresources/registered_resources.openapi.yaml
    • docs/openapi/policy/resourcemapping/resource_mapping.openapi.yaml
    • docs/openapi/policy/subjectmapping/subject_mapping.openapi.yaml
    • docs/openapi/policy/unsafe/unsafe.openapi.yaml
  • Ignored by pattern: protocol/**/* (2)
    • protocol/go/policy/actions/actions.pb.go
    • protocol/go/policy/objects.pb.go
Activity
  • The pull request description indicates that unit tests, integration tests, and documentation are yet to be updated, as the corresponding checklist items are unchecked.
  • No specific comments or reviews have been made on the pull request yet.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.


New fields now appear, Namespaces bring order clear, Code review, no fear.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a namespace field to the Action proto message, associating actions with namespaces and propagating this through the gRPC API. However, a critical security vulnerability has been identified: the backend implementation (Go code and SQL queries) has not been updated to utilize these new namespace fields, leading to a security bypass where namespace isolation is not enforced. Additionally, the breaking change in GetActionRequest will disrupt existing internal logic for updating and deleting actions. It is recommended to complete the implementation of namespace filtering in the backend and update internal service calls to ensure consistency and security. Furthermore, consider adding comments to the new namespace_id and namespace_fqn fields in actions.proto to improve clarity and maintainability.

Comment thread service/policy/actions/actions.proto
Comment thread service/policy/actions/actions.proto
Comment thread service/policy/actions/actions.proto Outdated
Comment thread service/policy/actions/actions.proto
Comment thread service/policy/actions/actions.proto
@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 193.977267ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 94.662308ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 388.352752ms
Throughput 257.50 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 39.723517405s
Average Latency 395.503409ms
Throughput 125.87 requests/second

@github-actions

Copy link
Copy Markdown
Contributor

@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 201.177151ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 100.039504ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 386.887671ms
Throughput 258.47 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 39.76450823s
Average Latency 395.841042ms
Throughput 125.74 requests/second

@github-actions

Copy link
Copy Markdown
Contributor

@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 199.263597ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 98.169658ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 372.608402ms
Throughput 268.38 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 38.886557239s
Average Latency 387.65259ms
Throughput 128.58 requests/second

@github-actions

Copy link
Copy Markdown
Contributor

@elizabethhealy
elizabethhealy marked this pull request as ready for review March 11, 2026 20:33
@elizabethhealy
elizabethhealy requested review from a team as code owners March 11, 2026 20:33
@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 179.326207ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 90.676606ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 367.847708ms
Throughput 271.85 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 39.435263476s
Average Latency 392.835515ms
Throughput 126.79 requests/second

Comment thread service/policy/actions/actions.proto Outdated

@alkalescent alkalescent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Generally looks good. Left one line specific comment and then I have more general comment: Should we make the namespace_id/namespace_fqn oneof fields optional for backwards compatibility pre-migration? At the very least it feels strange to require namespaces for the standard (immutable?) actions e.g. read.

c-r33d
c-r33d previously approved these changes Mar 11, 2026
@c-r33d

c-r33d commented Mar 11, 2026

Copy link
Copy Markdown
Contributor

Generally looks good. Left one line specific comment and then I have more general comment: Should we make the namespace_id/namespace_fqn oneof fields optional for backwards compatibility pre-migration? At the very least if feels weird to require namespaces for the standard actions e.g. read.

Maybe platform should have a default namespace that the standard actions live under?

@github-actions

Copy link
Copy Markdown
Contributor

@elizabethhealy

elizabethhealy commented Mar 12, 2026

Copy link
Copy Markdown
Member Author

Generally looks good. Left one line specific comment and then I have more general comment: Should we make the namespace_id/namespace_fqn oneof fields optional for backwards compatibility pre-migration? At the very least if feels weird to require namespaces for the standard actions e.g. read.

Maybe platform should have a default namespace that the standard actions live under?

@c-r33d @alkalescent the ticket specified "Standard actions create, read, update, delete remain immutable in the db and present within every namespace" and my current plan to do that is:

  • Add namespace_id to actions in the db (nullable for legacy compatibility).
  • Backfill standard actions (create/read/update/delete) for every existing namespace.
  • Ensure new namespaces automatically get those 4 standard actions (either in namespace-create transaction or DB trigger).

so overall it will be more rows but less branching. per-namespace standard actions trade some storage overhead for simpler and hopefully safer logic

lmk your thoughts

@elizabethhealy
elizabethhealy requested a review from c-r33d March 12, 2026 14:19
@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 191.222171ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 99.126163ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 406.587941ms
Throughput 245.95 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 41.708344308s
Average Latency 415.304412ms
Throughput 119.88 requests/second

@github-actions

Copy link
Copy Markdown
Contributor

@elizabethhealy
elizabethhealy added this pull request to the merge queue Mar 12, 2026
Merged via the queue into main with commit bedc9b3 Mar 12, 2026
36 checks passed
@elizabethhealy
elizabethhealy deleted the dspx-2540-action-protos-namespaced branch March 12, 2026 15:00
github-merge-queue Bot pushed a commit that referenced this pull request Mar 12, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.18.0](protocol/go/v0.17.0...protocol/go/v0.18.0)
(2026-03-12)


### ⚠ BREAKING CHANGES

* **policy:** add namespace field to Actions proto
([#3130](#3130))
* **policy:** namespace Registered Resources
([#3111](#3111))

### Features

* **policy:** add namespace field to Actions proto
([#3130](#3130))
([bedc9b3](bedc9b3))
* **policy:** namespace Registered Resources
([#3111](#3111))
([6db1883](6db1883))


### Bug Fixes

* **ci:** Upgrade toolchain version to 1.25.8
([#3116](#3116))
([e1b7882](e1b7882))
* **policy:** deprecate ListAttributeValues in favor of existing
GetAttribute ([#3108](#3108))
([7e17c2d](7e17c2d))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>
JBCongdon pushed a commit to JBCongdon/platform that referenced this pull request May 24, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.14.0](opentdf/platform@service/v0.13.0...service/v0.14.0)
(2026-04-21)


### ⚠ BREAKING CHANGES

* **sdk:** reclassify KAS 400 errors — distinguish tamper from
misconfiguration
([opentdf#3166](opentdf#3166))
* **policy:** optional namespace for RRs
([opentdf#3165](opentdf#3165))
* **policy:** Namespace subject mappings and subject condition sets.
([opentdf#3143](opentdf#3143))
* **policy:** Optional namespace on actions protos, NamespacedPolicy
feature flag ([opentdf#3155](opentdf#3155))
* **policy:** add namespaced actions schema and namespace-aware action
queries ([opentdf#3154](opentdf#3154))
* **policy:** only require namespace on GetAction if no id provided
([opentdf#3144](opentdf#3144))
* **policy:** add namespace field to Actions proto
([opentdf#3130](opentdf#3130))
* **policy:** namespace Registered Resources
([opentdf#3111](opentdf#3111))
* **policy:** add namespace field to RegisteredResource proto
([opentdf#3110](opentdf#3110))

### Features

* **authz:** Namespaced policy in decisioning
([opentdf#3226](opentdf#3226))
([0355934](opentdf@0355934))
* **cli:** migrate otdfctl into platform monorepo
([opentdf#3205](opentdf#3205))
([5177bec](opentdf@5177bec))
* fix tracing ([opentdf#3242](opentdf#3242))
([57e5680](opentdf@57e5680))
* **policy:** add GetObligationTrigger RPC
([opentdf#3318](opentdf#3318))
([d68e39d](opentdf@d68e39d))
* **policy:** add namespace field to Actions proto
([opentdf#3130](opentdf#3130))
([bedc9b3](opentdf@bedc9b3))
* **policy:** add namespace field to RegisteredResource proto
([opentdf#3110](opentdf#3110))
([04fd85d](opentdf@04fd85d))
* **policy:** add namespaced actions schema and namespace-aware action
queries ([opentdf#3154](opentdf#3154))
([c0443f1](opentdf@c0443f1))
* **policy:** add sort ListSubjectMappings API
([opentdf#3255](opentdf#3255))
([9d5d757](opentdf@9d5d757))
* **policy:** Add sort support listregisteredresources api
([opentdf#3312](opentdf#3312))
([91a3ff3](opentdf@91a3ff3))
* **policy:** add sort support to ListAttributes API
([opentdf#3223](opentdf#3223))
([ec3312f](opentdf@ec3312f))
* **policy:** add sort support to ListKeyAccessServer
([opentdf#3287](opentdf#3287))
([7fae2d7](opentdf@7fae2d7))
* **policy:** Add sort support to ListNamespaces API
([opentdf#3192](opentdf#3192))
([aac86cd](opentdf@aac86cd))
* **policy:** add sort support to listobligations api
([opentdf#3300](opentdf#3300))
([9221cac](opentdf@9221cac))
* **policy:** add sort support to ListSubjectConditionSets API
([opentdf#3272](opentdf#3272))
([9010f12](opentdf@9010f12))
* **policy:** add SortField proto and update PageRequest for sort
support ([opentdf#3187](opentdf#3187))
([6cf1862](opentdf@6cf1862))
* **policy:** Enforce same namespace when actions referenced downstream
([opentdf#3206](opentdf#3206))
([4b5463a](opentdf@4b5463a))
* **policy:** namespace Registered Resources
([opentdf#3111](opentdf#3111))
([6db1883](opentdf@6db1883))
* **policy:** Namespace subject mappings and condition sets
([opentdf#3172](opentdf#3172))
([6deed50](opentdf@6deed50))
* **policy:** Namespace subject mappings and subject condition sets.
([opentdf#3143](opentdf#3143))
([3006780](opentdf@3006780))
* **policy:** optional namespace for RRs
([opentdf#3165](opentdf#3165))
([8948018](opentdf@8948018))
* **policy:** rollback migration strategy for namespaced actions
([opentdf#3235](opentdf#3235))
([f7e5e01](opentdf@f7e5e01))
* **policy:** Seed existing namespaces with standard actions
([opentdf#3228](opentdf#3228))
([12136b0](opentdf@12136b0))
* **policy:** Seed namespaces with standard actions on creation +
namespaced actions for obligation triggers
([opentdf#3161](opentdf#3161))
([984d76b](opentdf@984d76b))


### Bug Fixes

* **ci:** Upgrade toolchain version to 1.25.8
([opentdf#3116](opentdf#3116))
([e1b7882](opentdf@e1b7882))
* **core:** do not concat slashes directly in url/file paths
([opentdf#3290](opentdf#3290))
([114c2a7](opentdf@114c2a7))
* **deps:** bump github.com/jackc/pgx/v5 from 5.7.5 to 5.9.0 in /service
([opentdf#3316](opentdf#3316))
([017362e](opentdf@017362e))
* **deps:** bump github.com/opentdf/platform/lib/identifier from 0.2.0
to 0.3.0 in /service
([opentdf#3162](opentdf#3162))
([8bc5dcd](opentdf@8bc5dcd))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.16.0 to
0.17.0 in /service
([opentdf#3125](opentdf#3125))
([29fec61](opentdf@29fec61))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.17.0 to
0.21.0 in /service
([opentdf#3220](opentdf#3220))
([e63add2](opentdf@e63add2))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.21.0 to
0.22.0 in /service
([opentdf#3248](opentdf#3248))
([1ebce73](opentdf@1ebce73))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.22.0 to
0.23.0 in /service
([opentdf#3271](opentdf#3271))
([3338b8e](opentdf@3338b8e))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.23.0 to
0.24.0 in /service
([opentdf#3321](opentdf#3321))
([78e6022](opentdf@78e6022))
* **deps:** bump github.com/opentdf/platform/protocol/go from 0.24.0 to
0.25.0 in /service
([opentdf#3333](opentdf#3333))
([3940bf8](opentdf@3940bf8))
* **deps:** bump github.com/opentdf/platform/sdk from 0.13.0 to 0.16.0
in /service ([opentdf#3356](opentdf#3356))
([5617077](opentdf@5617077))
* **deps:** bump
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from
1.42.0 to 1.43.0 in /service
([opentdf#3282](opentdf#3282))
([046374a](opentdf@046374a))
* **deps:** bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in
/service ([opentdf#3281](opentdf#3281))
([56b33f2](opentdf@56b33f2))
* **deps:** bump google.golang.org/grpc from 1.77.0 to 1.79.3 in
/service ([opentdf#3176](opentdf#3176))
([3289502](opentdf@3289502))
* **deps:** remove direct github.com/docker/docker dependency
([opentdf#3229](opentdf#3229))
([2becb27](opentdf@2becb27))
* **deps:** upgrade testcontainers-go to resolve vulns
([opentdf#3299](opentdf#3299))
([72c6f9b](opentdf@72c6f9b))
* **ers:** include standard JWT claims in claims mode entity resolution
([opentdf#3196](opentdf#3196))
([6d50da1](opentdf@6d50da1))
* **ers:** ldap multi-strategy ers
([opentdf#3117](opentdf#3117))
([d3aaf1a](opentdf@d3aaf1a))
* **policy:** deprecate ListAttributeValues in favor of existing
GetAttribute ([opentdf#3108](opentdf#3108))
([7e17c2d](opentdf@7e17c2d))
* **policy:** make obligation trigger uniqueness client-aware
([opentdf#3114](opentdf#3114))
([9265bc3](opentdf@9265bc3))
* **policy:** omit empty attribute values from create responses
([opentdf#3193](opentdf#3193))
([d298378](opentdf@d298378))
* **policy:** only require namespace on GetAction if no id provided
([opentdf#3144](opentdf#3144))
([10d0c0f](opentdf@10d0c0f))
* **policy:** Optional namespace on actions protos, NamespacedPolicy
feature flag ([opentdf#3155](opentdf#3155))
([c20f039](opentdf@c20f039))
* **policy:** order List* results by created_at
([opentdf#3088](opentdf#3088))
([ea90ac2](opentdf@ea90ac2))
* **sdk:** normalize issuer URL before OIDC discovery
([opentdf#3261](opentdf#3261))
([61f98c9](opentdf@61f98c9))
* **sdk:** reclassify KAS 400 errors — distinguish tamper from
misconfiguration
([opentdf#3166](opentdf#3166))
([f04a385](opentdf@f04a385))
* **sdk:** remove testcontainers from consumer dependency graph
([opentdf#3129](opentdf#3129))
([f17dcdd](opentdf@f17dcdd))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp:policy Policy Configuration ( attributes, subject mappings, resource mappings, kas registry) docs Documentation size/s

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants