Skip to content

ogar-rbac: GrantSource::scope_of (row scope from the grant source) - #323

Merged
AdaWorldAPI merged 4 commits into
mainfrom
ccr-0455e606-wmtsor
Oct 8, 2026
Merged

AdaWorldAPI merged 4 commits into
mainfrom
ccr-0455e606-wmtsor

Conversation

@AdaWorldAPI

@AdaWorldAPI AdaWorldAPI commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

ClassRbac::row_scope(role, class) on OgarRbac always returned the default scope, so a grant source had no way to supply axis-3 row scope. This PR adds GrantSource::scope_of(&self, role, class) -> Option<ScopeSpec>. It defaults to None, so every existing source behaves as before. OgarRbac::row_scope delegates to it.

The new test a_sources_row_scope_travels_with_the_decision uses the nested ScopePath from AdaWorldAPI/lance-graph#1401, which has merged. Removing the delegation fails the test.

This PR earlier also minted an auth_surrealdb (0x0B05) profile and added a SurrealDB write-up. Both are removed: SurrealDB was a pattern to study, not a provider of this stack. The lance-graph mirror row comes out in the paired lance-graph PR.

Tests

ogar-rbac: 8 pass. clippy -D warnings is clean for ogar-rbac, ogar-vocab and ogar-class-view.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg

claude added 3 commits October 8, 2026 00:39
…profile

is-a auth_store, like the Zitadel / Zanzibar / Ory Keto profiles. Claims:
subject ID, roles RL, namespace NS; DB and AC narrow the scope. Paired with
the lance-graph contract mirror row and AuthProvider::SurrealDb (merge
together). Count pins moved 98 -> 99 (class_ids::ALL) and 4 -> 5 (Auth).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
A provider-agnostic hook, default None (global), so every existing source
is unchanged. OgarRbac::row_scope delegates to it; authorize_scoped folds
the scopes of the granting roles. Needs ScopePath from lance-graph
(contract::rbac), so this lands after the paired lance-graph PR.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
SurrealDB's authorization (levels, Viewer/Editor/Owner, View/Edit, 21
resource kinds, the is_allowed_check rules, the ID/RL/NS/DB/AC claims)
mapped onto the four axes, with nested levels as ScopePath on axis 3.
Records what landed and the four things that still block the bit-for-bit
equivalence probe.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 1ffb9c69-5ff7-4282-b623-1ee2b45b82c8
📥 Commits

Reviewing files that changed from the base of the PR and between 2e1b87b and 0e891ef.

📒 Files selected for processing (6)
  • .claude/board/LATEST_STATE.md
  • crates/ogar-class-view/src/lib.rs
  • crates/ogar-rbac/src/lib.rs
  • crates/ogar-vocab/src/capability_registry.rs
  • crates/ogar-vocab/src/lib.rs
  • docs/SURREALDB-IAM-HARVEST.md

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.


📝 Walkthrough

Walkthrough

The Auth vocabulary and canonical class registry now include the SurrealDB profile. RBAC grant sources can optionally provide role-bound row scopes, which OgarRbac forwards. New documentation describes SurrealDB IAM concepts, their mapping to OGAR, and identified equivalence gaps.

Changes

SurrealDB IAM support

Layer / File(s) Summary
Register the SurrealDB Auth profile
crates/ogar-vocab/src/lib.rs, crates/ogar-vocab/src/capability_registry.rs, crates/ogar-class-view/src/lib.rs, .claude/board/LATEST_STATE.md, docs/SURREALDB-IAM-HARVEST.md
Adds Auth class ID 0x0B05, its class builder, and registry entries. Updates class-count and domain-resolution checks. The documentation describes SurrealDB IAM concepts and authorization rules.
Forward role-bound row scopes
crates/ogar-rbac/src/lib.rs, docs/SURREALDB-IAM-HARVEST.md
Adds GrantSource::scope_of, defaulting to None, and forwards the result through OgarRbac::row_scope. Tests check scope propagation and path matching. The documentation maps row scope to OGAR and lists equivalence gaps.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Suggested reviewers: claude

Merge Risk: 🔵 Low · up to 58363

This PR adds a SurrealDB IAM profile and optional role-bound row scopes. The ogar-rbac crate will not build until the paired lance-graph PR #1401 merges, so merge that one first.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 70.59% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 17 functions across 4 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the added GrantSource::scope_of row-scope behavior, which is a substantial part of the pull request. It does not mention the SurrealDB vocabulary and documentation changes,…
Full details: Docstring Coverage

Explanation

Docstring coverage is 70.59% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 17 functions across 4 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit reads the scope path with care,
SurrealDB joins the Auth class there.
A grant may carry a nested route,
Descendants pass; siblings are out.
The burrow’s codebook gains one more.

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

The cargo clippy -D warnings failure is the expected pairing gap with AdaWorldAPI/lance-graph#1401, not a defect in this PR.

ogar-rbac depends on lance-graph's main branch, which does not have ScopePath, ScopeSpec.path or ScopeSpec::admits yet. The four errors (E0432, E0560 and E0599) all name those items.

Against the #1401 branch, ogar-rbac builds and its 8 tests pass. I checked that locally through a --config patch; nothing is committed for it.

Once #1401 merges, a re-run of this check should go green with no change here. Merge lance-graph#1401 first.


Generated by Claude Code

@AdaWorldAPI
AdaWorldAPI marked this pull request as ready for review October 8, 2026 05:01
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T05:04:15.700473Z 0e891ef Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

SurrealDB was meant as a pattern to study, not as an auth provider of this
stack. Drops the 0x0B05 mint, its class-view row, the count pins and the
harvest doc. The generic GrantSource::scope_of hook stays.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G22yT6htkcdyXsihxxXdrg
@AdaWorldAPI AdaWorldAPI changed the title IAM: mint auth_surrealdb, GrantSource::scope_of, harvest SurrealDB core IAM ogar-rbac: GrantSource::scope_of (row scope from the grant source) Oct 8, 2026
@AdaWorldAPI
AdaWorldAPI merged commit fca2380 into main Oct 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants