feat(policy): Namespace subject mappings and condition sets - #3172
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request enhances the policy service by introducing namespace awareness to subject mappings and subject condition sets. This change allows for better organization and isolation of policy definitions within a multi-tenant or segmented environment. It also includes robust validation to maintain data integrity by ensuring that all related policy components adhere to the same namespace, preventing cross-namespace policy misconfigurations. Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Ignored Files
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. A policy defined, In namespaces, neatly aligned, Order in the code. Footnotes
|
There was a problem hiding this comment.
Code Review
The pull request introduces namespace scoping for SubjectConditionSet and SubjectMapping entities, involving database schema changes, updated protobuf definitions, and refactored Go service and database logic to support namespace-aware creation, retrieval, and consistency checks. Review feedback suggests improving error messages for namespace consistency validation, optimizing the CreateSubjectMapping function to avoid a redundant GetSubjectMapping call, and adding more test cases for various namespace configurations.
e9ec75d to
e04d713
Compare
X-Test Failure Report |
X-Test Failure Report |
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
X-Test Failure Reporttest-cases-mapping-report |
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
📝 WalkthroughWalkthroughThis PR extends subject mappings and subject condition sets with optional namespace scoping. Changes include database migrations adding Changes
Sequence DiagramsequenceDiagram
participant Client
participant ServiceAPI as Service API Handler
participant DB as Policy DB Client
participant DBConn as Database
Client->>ServiceAPI: CreateSubjectMapping(request with NamespaceId/Fqn)
ServiceAPI->>DB: resolveNamespace(namespaceID/fqn)
DB->>DBConn: Query attribute_namespaces
DBConn-->>DB: namespace record
DB-->>ServiceAPI: resolved namespaceID
ServiceAPI->>DB: resolveSubjectMappingActions(action names/ids, namespaceID)
DB->>DBConn: createOrListActionsByNameInNamespace
DBConn-->>DB: existing + newly created actions
DB-->>ServiceAPI: action IDs with namespace info
ServiceAPI->>DB: resolveSubjectConditionSet(condition, namespaceID)
DB->>DBConn: Query/create subject_condition_set in namespace
DBConn-->>DB: SCS ID with namespace
DB-->>ServiceAPI: SCS details
ServiceAPI->>DB: validateSubjectMappingNamespaceConsistency
Note over DB: Check attribute value, actions,<br/>and SCS all in same namespace
DB-->>ServiceAPI: validation result
alt Validation passes
ServiceAPI->>DB: createSubjectMapping(with NamespaceID)
DB->>DBConn: INSERT subject_mappings with namespace_id
DBConn-->>DB: created mapping ID
DB->>DBConn: Query full mapping data
DBConn-->>DB: mapping with namespace details
DB-->>ServiceAPI: SubjectMapping object
ServiceAPI-->>Client: success response
else Validation fails
ServiceAPI-->>Client: CodeInvalidArgument (ErrNamespaceMismatch)
end
Estimated Code Review Effort🎯 4 (Complex) | ⏱️ ~50 minutes
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (2)
service/integration/subject_mappings_test.go (2)
629-638:⚠️ Potential issue | 🟠 MajorTest defined on wrong suite receiver.
Test_ListSubjectMappings_Limit_TooLarge_Failsis defined onNamespacesSuiteinstead ofSubjectMappingsSuite. This will cause the test to run in the wrong suite context and may fail or not execute as intended.🐛 Proposed fix
-func (s *NamespacesSuite) Test_ListSubjectMappings_Limit_TooLarge_Fails() { +func (s *SubjectMappingsSuite) Test_ListSubjectMappings_Limit_TooLarge_Fails() {🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@service/integration/subject_mappings_test.go` around lines 629 - 638, The test method Test_ListSubjectMappings_Limit_TooLarge_Fails is declared with the wrong suite receiver (NamespacesSuite) so it will run in the wrong context; change its receiver to SubjectMappingsSuite by updating the method signature to use (s *SubjectMappingsSuite) so the test executes under the correct suite and has access to SubjectMappingsSuite fields and helpers (keep the body unchanged except for the receiver).
1111-1120:⚠️ Potential issue | 🟠 MajorTest defined on wrong suite receiver.
Test_ListSubjectConditionSets_Limit_TooLarge_Failsis defined onNamespacesSuiteinstead ofSubjectMappingsSuite. This causes the test to run in a different test suite context.🐛 Proposed fix
-func (s *NamespacesSuite) Test_ListSubjectConditionSets_Limit_TooLarge_Fails() { +func (s *SubjectMappingsSuite) Test_ListSubjectConditionSets_Limit_TooLarge_Fails() {🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@service/integration/subject_mappings_test.go` around lines 1111 - 1120, The test method Test_ListSubjectConditionSets_Limit_TooLarge_Fails is declared with the wrong receiver (NamespacesSuite); change its receiver to SubjectMappingsSuite so the test runs in the correct suite context (i.e., update the method signature from func (s *NamespacesSuite) Test_ListSubjectConditionSets_Limit_TooLarge_Fails() to func (s *SubjectMappingsSuite) Test_ListSubjectConditionSets_Limit_TooLarge_Fails()), ensuring SubjectMappingsSuite is the intended suite type in the same file or package.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In
`@service/policy/db/migrations/20260318000000_add_namespace_to_subject_mappings.md`:
- Around line 24-31: Update the inaccurate bullet about unscoped records: change
the statement that "Existing records with `namespace_id = NULL` are unscoped and
returned in all list queries regardless of namespace filter" to state that
records with `namespace_id = NULL` are returned only when no namespace filter is
provided; when a specific namespace filter is supplied the NULL records are
excluded (since `NULL = <value>` evaluates to false in SQL), and keep the rest
of the documented behaviors (optional namespace at creation, list queries
accepting an optional namespace filter, and cascade delete) unchanged.
In `@service/policy/db/queries/actions.sql`:
- Around line 147-180: The query can silently insert actions with namespace_id =
NULL when resolved_namespace is not found; update the CTE flow so operations
only proceed if a namespace was resolved: add a namespace_id_check CTE that
selects id FROM resolved_namespace WHERE id IS NOT NULL and then replace
references to (SELECT id FROM resolved_namespace) in existing_actions and in the
INSERT in new_actions with (SELECT id FROM namespace_id_check), and also add a
WHERE EXISTS (SELECT 1 FROM namespace_id_check) guard before the INSERT SELECT
so no rows are created when namespace is missing (alternatively make the
function raise an error when namespace_id_check is empty if callers expect
failure); this touches the resolved_namespace, namespace_id_check (new),
existing_actions, new_actions and the createOrListActionsByNameInNamespace
usage.
In `@service/policy/db/queries/subject_mappings.sql`:
- Line 1: Replace the bare divider line
'----------------------------------------------------------------' at the top of
subject_mappings.sql with a proper SQL comment by prefixing it with '--' (e.g.,
change it to a commented header like '--
-------------------------------------------------------------' or include a
descriptive comment such as '-- SUBJECT CONDITION SETS' followed by the dashed
comment); this removes the syntax error by ensuring the divider is treated as a
comment.
- Around line 72-74: The delimiter lines surrounding the SUBJECT MAPPINGS header
are missing SQL comment prefixes; update the two delimiter lines that flank the
"-- SUBJECT MAPPINGS" header in subject_mappings.sql so each starts with "--"
(i.e., change the bare
"----------------------------------------------------------------" lines to
commented delimiter lines) to ensure they are valid SQL comments and don't break
parsing.
---
Outside diff comments:
In `@service/integration/subject_mappings_test.go`:
- Around line 629-638: The test method
Test_ListSubjectMappings_Limit_TooLarge_Fails is declared with the wrong suite
receiver (NamespacesSuite) so it will run in the wrong context; change its
receiver to SubjectMappingsSuite by updating the method signature to use (s
*SubjectMappingsSuite) so the test executes under the correct suite and has
access to SubjectMappingsSuite fields and helpers (keep the body unchanged
except for the receiver).
- Around line 1111-1120: The test method
Test_ListSubjectConditionSets_Limit_TooLarge_Fails is declared with the wrong
receiver (NamespacesSuite); change its receiver to SubjectMappingsSuite so the
test runs in the correct suite context (i.e., update the method signature from
func (s *NamespacesSuite) Test_ListSubjectConditionSets_Limit_TooLarge_Fails()
to func (s *SubjectMappingsSuite)
Test_ListSubjectConditionSets_Limit_TooLarge_Fails()), ensuring
SubjectMappingsSuite is the intended suite type in the same file or package.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 1143ca26-68be-46de-884e-f51d04bb76ad
📒 Files selected for processing (13)
service/integration/subject_mappings_test.goservice/pkg/db/errors.goservice/policy/db/actions.sql.goservice/policy/db/migrations/20260318000000_add_namespace_to_subject_mappings.mdservice/policy/db/migrations/20260318000000_add_namespace_to_subject_mappings.sqlservice/policy/db/models.goservice/policy/db/queries/actions.sqlservice/policy/db/queries/subject_mappings.sqlservice/policy/db/schema_erd.mdservice/policy/db/subject_mappings.goservice/policy/db/subject_mappings.sql.goservice/policy/db/utils.goservice/policy/subjectmapping/subject_mapping.go
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In
`@service/policy/db/migrations/20260318000000_add_namespace_to_subject_mappings.md`:
- Around line 26-27: Remove the dangling contradictory sentence fragment on Line
27 in the migration doc so the behavior is clear: keep the sentence that states
"Existing records with `namespace_id = NULL` are unscoped and returned in all
list queries where no namespace filter is given." (the corrected semantics) and
delete the extra orphan fragment that follows it; ensure the final file reflects
that NULL `namespace_id` is intentional for legacy/global records until
`NamespacedPolicy` is enabled.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 31e024d1-832f-4500-bede-a7ec0ab1c541
📒 Files selected for processing (1)
service/policy/db/migrations/20260318000000_add_namespace_to_subject_mappings.md
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
There was a problem hiding this comment.
♻️ Duplicate comments (2)
service/policy/db/queries/subject_mappings.sql (2)
1-3:⚠️ Potential issue | 🔴 CriticalMissing SQL comment prefix causes syntax error.
Line 1 starts with
----------------------------------------------------------------which should be a comment, but it's missing the--prefix. This will cause a SQL syntax error when the file is parsed by sqlc or executed directly.🐛 Proposed fix
----------------------------------------------------------------- +-- ------------------------------------------------------------ -- SUBJECT CONDITION SETS ----------------------------------------------------------------- +-- ------------------------------------------------------------🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@service/policy/db/queries/subject_mappings.sql` around lines 1 - 3, The leading separator lines in subject_mappings.sql are not commented and will cause SQL parse errors; update each separator line like the ones starting with "----------------------------------------------------------------" (and similar header/footer separator lines) to include the SQL comment prefix (--) so they become proper comments; ensure every human-readable header line (e.g., "SUBJECT CONDITION SETS") is also prefixed with -- to avoid syntax errors when sqlc or the SQL engine parses the file.
64-66:⚠️ Potential issue | 🔴 CriticalSame issue: missing comment prefix.
Line 64 has the same problem with the delimiter missing the
--prefix.🐛 Proposed fix
----------------------------------------------------------------- +-- ------------------------------------------------------------ -- SUBJECT MAPPINGS ----------------------------------------------------------------- +-- ------------------------------------------------------------🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@service/policy/db/queries/subject_mappings.sql` around lines 64 - 66, The file contains a header delimiter line missing the SQL comment prefix; update the delimiter before the "SUBJECT MAPPINGS" header so it starts with "--" (i.e., ensure the separator line uses the "--" prefix like the surrounding comment blocks) to make it a valid SQL comment; locate the delimiter near the "SUBJECT MAPPINGS" header in subject_mappings.sql and add the missing "--" at the start of that line.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In `@service/policy/db/queries/subject_mappings.sql`:
- Around line 1-3: The leading separator lines in subject_mappings.sql are not
commented and will cause SQL parse errors; update each separator line like the
ones starting with
"----------------------------------------------------------------" (and similar
header/footer separator lines) to include the SQL comment prefix (--) so they
become proper comments; ensure every human-readable header line (e.g., "SUBJECT
CONDITION SETS") is also prefixed with -- to avoid syntax errors when sqlc or
the SQL engine parses the file.
- Around line 64-66: The file contains a header delimiter line missing the SQL
comment prefix; update the delimiter before the "SUBJECT MAPPINGS" header so it
starts with "--" (i.e., ensure the separator line uses the "--" prefix like the
surrounding comment blocks) to make it a valid SQL comment; locate the delimiter
near the "SUBJECT MAPPINGS" header in subject_mappings.sql and add the missing
"--" at the start of that line.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: ff3845e8-c936-416b-b077-24ad5c26357d
📒 Files selected for processing (6)
service/integration/subject_mappings_test.goservice/policy/db/actions.sql.goservice/policy/db/queries/actions.sqlservice/policy/db/queries/subject_mappings.sqlservice/policy/db/subject_mappings.goservice/policy/db/subject_mappings.sql.go
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
🤖 I have created a release *beep* *boop* --- ## [0.14.0](opentdf/platform@service/v0.13.0...service/v0.14.0) (2026-04-21) ### ⚠ BREAKING CHANGES * **sdk:** reclassify KAS 400 errors — distinguish tamper from misconfiguration ([opentdf#3166](opentdf#3166)) * **policy:** optional namespace for RRs ([opentdf#3165](opentdf#3165)) * **policy:** Namespace subject mappings and subject condition sets. ([opentdf#3143](opentdf#3143)) * **policy:** Optional namespace on actions protos, NamespacedPolicy feature flag ([opentdf#3155](opentdf#3155)) * **policy:** add namespaced actions schema and namespace-aware action queries ([opentdf#3154](opentdf#3154)) * **policy:** only require namespace on GetAction if no id provided ([opentdf#3144](opentdf#3144)) * **policy:** add namespace field to Actions proto ([opentdf#3130](opentdf#3130)) * **policy:** namespace Registered Resources ([opentdf#3111](opentdf#3111)) * **policy:** add namespace field to RegisteredResource proto ([opentdf#3110](opentdf#3110)) ### Features * **authz:** Namespaced policy in decisioning ([opentdf#3226](opentdf#3226)) ([0355934](opentdf@0355934)) * **cli:** migrate otdfctl into platform monorepo ([opentdf#3205](opentdf#3205)) ([5177bec](opentdf@5177bec)) * fix tracing ([opentdf#3242](opentdf#3242)) ([57e5680](opentdf@57e5680)) * **policy:** add GetObligationTrigger RPC ([opentdf#3318](opentdf#3318)) ([d68e39d](opentdf@d68e39d)) * **policy:** add namespace field to Actions proto ([opentdf#3130](opentdf#3130)) ([bedc9b3](opentdf@bedc9b3)) * **policy:** add namespace field to RegisteredResource proto ([opentdf#3110](opentdf#3110)) ([04fd85d](opentdf@04fd85d)) * **policy:** add namespaced actions schema and namespace-aware action queries ([opentdf#3154](opentdf#3154)) ([c0443f1](opentdf@c0443f1)) * **policy:** add sort ListSubjectMappings API ([opentdf#3255](opentdf#3255)) ([9d5d757](opentdf@9d5d757)) * **policy:** Add sort support listregisteredresources api ([opentdf#3312](opentdf#3312)) ([91a3ff3](opentdf@91a3ff3)) * **policy:** add sort support to ListAttributes API ([opentdf#3223](opentdf#3223)) ([ec3312f](opentdf@ec3312f)) * **policy:** add sort support to ListKeyAccessServer ([opentdf#3287](opentdf#3287)) ([7fae2d7](opentdf@7fae2d7)) * **policy:** Add sort support to ListNamespaces API ([opentdf#3192](opentdf#3192)) ([aac86cd](opentdf@aac86cd)) * **policy:** add sort support to listobligations api ([opentdf#3300](opentdf#3300)) ([9221cac](opentdf@9221cac)) * **policy:** add sort support to ListSubjectConditionSets API ([opentdf#3272](opentdf#3272)) ([9010f12](opentdf@9010f12)) * **policy:** add SortField proto and update PageRequest for sort support ([opentdf#3187](opentdf#3187)) ([6cf1862](opentdf@6cf1862)) * **policy:** Enforce same namespace when actions referenced downstream ([opentdf#3206](opentdf#3206)) ([4b5463a](opentdf@4b5463a)) * **policy:** namespace Registered Resources ([opentdf#3111](opentdf#3111)) ([6db1883](opentdf@6db1883)) * **policy:** Namespace subject mappings and condition sets ([opentdf#3172](opentdf#3172)) ([6deed50](opentdf@6deed50)) * **policy:** Namespace subject mappings and subject condition sets. ([opentdf#3143](opentdf#3143)) ([3006780](opentdf@3006780)) * **policy:** optional namespace for RRs ([opentdf#3165](opentdf#3165)) ([8948018](opentdf@8948018)) * **policy:** rollback migration strategy for namespaced actions ([opentdf#3235](opentdf#3235)) ([f7e5e01](opentdf@f7e5e01)) * **policy:** Seed existing namespaces with standard actions ([opentdf#3228](opentdf#3228)) ([12136b0](opentdf@12136b0)) * **policy:** Seed namespaces with standard actions on creation + namespaced actions for obligation triggers ([opentdf#3161](opentdf#3161)) ([984d76b](opentdf@984d76b)) ### Bug Fixes * **ci:** Upgrade toolchain version to 1.25.8 ([opentdf#3116](opentdf#3116)) ([e1b7882](opentdf@e1b7882)) * **core:** do not concat slashes directly in url/file paths ([opentdf#3290](opentdf#3290)) ([114c2a7](opentdf@114c2a7)) * **deps:** bump github.com/jackc/pgx/v5 from 5.7.5 to 5.9.0 in /service ([opentdf#3316](opentdf#3316)) ([017362e](opentdf@017362e)) * **deps:** bump github.com/opentdf/platform/lib/identifier from 0.2.0 to 0.3.0 in /service ([opentdf#3162](opentdf#3162)) ([8bc5dcd](opentdf@8bc5dcd)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.16.0 to 0.17.0 in /service ([opentdf#3125](opentdf#3125)) ([29fec61](opentdf@29fec61)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.17.0 to 0.21.0 in /service ([opentdf#3220](opentdf#3220)) ([e63add2](opentdf@e63add2)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.21.0 to 0.22.0 in /service ([opentdf#3248](opentdf#3248)) ([1ebce73](opentdf@1ebce73)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.22.0 to 0.23.0 in /service ([opentdf#3271](opentdf#3271)) ([3338b8e](opentdf@3338b8e)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.23.0 to 0.24.0 in /service ([opentdf#3321](opentdf#3321)) ([78e6022](opentdf@78e6022)) * **deps:** bump github.com/opentdf/platform/protocol/go from 0.24.0 to 0.25.0 in /service ([opentdf#3333](opentdf#3333)) ([3940bf8](opentdf@3940bf8)) * **deps:** bump github.com/opentdf/platform/sdk from 0.13.0 to 0.16.0 in /service ([opentdf#3356](opentdf#3356)) ([5617077](opentdf@5617077)) * **deps:** bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.42.0 to 1.43.0 in /service ([opentdf#3282](opentdf#3282)) ([046374a](opentdf@046374a)) * **deps:** bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 in /service ([opentdf#3281](opentdf#3281)) ([56b33f2](opentdf@56b33f2)) * **deps:** bump google.golang.org/grpc from 1.77.0 to 1.79.3 in /service ([opentdf#3176](opentdf#3176)) ([3289502](opentdf@3289502)) * **deps:** remove direct github.com/docker/docker dependency ([opentdf#3229](opentdf#3229)) ([2becb27](opentdf@2becb27)) * **deps:** upgrade testcontainers-go to resolve vulns ([opentdf#3299](opentdf#3299)) ([72c6f9b](opentdf@72c6f9b)) * **ers:** include standard JWT claims in claims mode entity resolution ([opentdf#3196](opentdf#3196)) ([6d50da1](opentdf@6d50da1)) * **ers:** ldap multi-strategy ers ([opentdf#3117](opentdf#3117)) ([d3aaf1a](opentdf@d3aaf1a)) * **policy:** deprecate ListAttributeValues in favor of existing GetAttribute ([opentdf#3108](opentdf#3108)) ([7e17c2d](opentdf@7e17c2d)) * **policy:** make obligation trigger uniqueness client-aware ([opentdf#3114](opentdf#3114)) ([9265bc3](opentdf@9265bc3)) * **policy:** omit empty attribute values from create responses ([opentdf#3193](opentdf#3193)) ([d298378](opentdf@d298378)) * **policy:** only require namespace on GetAction if no id provided ([opentdf#3144](opentdf#3144)) ([10d0c0f](opentdf@10d0c0f)) * **policy:** Optional namespace on actions protos, NamespacedPolicy feature flag ([opentdf#3155](opentdf#3155)) ([c20f039](opentdf@c20f039)) * **policy:** order List* results by created_at ([opentdf#3088](opentdf#3088)) ([ea90ac2](opentdf@ea90ac2)) * **sdk:** normalize issuer URL before OIDC discovery ([opentdf#3261](opentdf#3261)) ([61f98c9](opentdf@61f98c9)) * **sdk:** reclassify KAS 400 errors — distinguish tamper from misconfiguration ([opentdf#3166](opentdf#3166)) ([f04a385](opentdf@f04a385)) * **sdk:** remove testcontainers from consumer dependency graph ([opentdf#3129](opentdf#3129)) ([f17dcdd](opentdf@f17dcdd)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>
Proposed Changes
1.) Add optional namespacing to subject mappings and condition sets.
2.) Policy constructs that make up subject mappings must be of the same namespace, if a top-level namespace is defined.
3.) Guard required namespacing behind feature flag
Checklist
Testing Instructions
Summary by CodeRabbit
Release Notes
New Features
Database