Documentation
¶
Overview ¶
Package language parses and validates FGA mapping configurations.
It transforms mapping YAML into a MappingConfig, checks structural constraints via MappingConfig.Validate, and stamps source positions onto the parsed structs so downstream consumers (the mapper package, IDE tooling) can attach diagnostics without reaching into the YAML AST. It performs no expression compilation or evaluation — that is the mapper package's responsibility.
Index ¶
Constants ¶
const ( // DefaultMaxRules is the default cap on the number of rules a single mapping // file may declare. Override per-call with WithMaxRules. DefaultMaxRules = 100 )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Iterator ¶
type Iterator struct {
Source string `yaml:"source"`
As string `yaml:"as"`
Tuples []ParsedTuple `yaml:"tuples"`
SourcePos Position `yaml:"-"` // source position of the iterator source expression, stamped at parse time
}
Iterator represents a fan-out configuration that iterates over a collection.
type MappingConfig ¶
type MappingConfig struct {
Version string `yaml:"version"`
Rules []Rule `yaml:"rules"`
Tests []TestCase `yaml:"tests,omitempty"`
// contains filtered or unexported fields
}
MappingConfig is the top-level structure parsed from a mapping YAML file. It contains the schema version, an ordered list of rules, and optional embedded test cases.
func Parse ¶
func Parse(data []byte) (*MappingConfig, error)
Parse parses a YAML mapping file and returns the MappingConfig without compiling. Useful for inspecting rule structure (when guards, variables, tuple templates) without running full expression compilation.
func (*MappingConfig) ClearRoot ¶
func (m *MappingConfig) ClearRoot()
ClearRoot releases the retained YAML AST node tree so it can be garbage collected. Source positions are stamped onto the parsed structs at parse time, so they survive; only Validate's ability to look up positions for structural errors depends on the tree. Call this once, after the final Validate, when a long-lived MappingConfig no longer needs position lookup — the compiled mapping reads only the flat Position fields, never the tree.
func (*MappingConfig) Validate ¶
func (m *MappingConfig) Validate(opts ...ValidateOption) error
Validate checks structural constraints on a parsed MappingConfig. Source positions are attached to errors using the YAML node tree stored during parsing. Returns a joined error tree containing one or more *ValidationError values, or nil if the configuration is valid.
Validate does not consume the AST node tree; it may be called repeatedly and still attach source positions. Callers done with position data should call ClearRoot to release the tree for garbage collection.
type ParsedTuple ¶
type ParsedTuple struct {
When string `yaml:"when,omitempty"`
Action TupleAction `yaml:"action,omitempty"`
User string `yaml:"user"`
Relation string `yaml:"relation"`
Object string `yaml:"object"`
Condition string `yaml:"condition,omitempty"` // FGA condition name
Context map[string]string `yaml:"context,omitempty"` // FGA context (values are interpolation templates)
// Source positions stamped at parse time so the mapper can attach diagnostics
// to compiled interpolations without reaching back into the YAML AST.
WhenPos Position `yaml:"-"`
UserPos Position `yaml:"-"`
RelationPos Position `yaml:"-"`
ObjectPos Position `yaml:"-"`
ContextPos map[string]Position `yaml:"-"`
}
ParsedTuple is a tuple parsed from YAML whose User, Relation, and Object fields are interpolated strings rendered against the evaluation context (input, variables, iterator value).
type ParsedTupleFilter ¶
type ParsedTupleFilter struct {
User string `yaml:"user,omitempty"`
Relation string `yaml:"relation,omitempty"`
Object string `yaml:"object,omitempty"`
Action TupleFilterAction `yaml:"action,omitempty"`
UserPos Position `yaml:"-"`
RelationPos Position `yaml:"-"`
ObjectPos Position `yaml:"-"`
}
ParsedTupleFilter is a tuple filter parsed from YAML. Object is a required interpolated string; User and Relation are optional interpolated strings. Empty rendered fields act as wildcards.
The *Pos fields carry the source position of each interpolated field, stamped at parse time so the mapper can attach diagnostics without reaching back into the YAML AST.
type Position ¶
type Position struct {
StartLine int `json:"startLine"`
StartColumn int `json:"startColumn"`
EndLine int `json:"endLine"`
EndColumn int `json:"endColumn"`
}
Position represents a source location range in a YAML file. All fields are 1-based. A value of 0 means the position is unknown. Parent structs use json:"omitzero" to omit zero-valued positions from JSON.
type Rule ¶
type Rule struct {
Name string `yaml:"name"`
When string `yaml:"when,omitempty"`
Action TupleAction `yaml:"action,omitempty"`
RawVariables any `yaml:"variables,omitempty"` // sink for strict YAML; unused -- variables extracted from AST
Variables Variables `yaml:"-"`
TupleFilters []ParsedTupleFilter `yaml:"tuple_filters,omitempty"`
Iterator *Iterator `yaml:"iterator,omitempty"`
Tuples []ParsedTuple `yaml:"tuples"`
WhenPos Position `yaml:"-"` // source position of the when guard, stamped at parse time
}
Rule defines a mapping from an input event to one or more tuples. Each rule optionally filters via a When guard (Expr), computes Variables (Expr), iterates over a collection, and renders Tuples via interpolated strings ({{ expr }}).
type TestCase ¶
type TestCase struct {
Name string `yaml:"name"`
Input map[string]any `yaml:"input"`
ExpectTuples []Tuple `yaml:"expect_tuples"`
ExpectTupleFilters []TupleFilter `yaml:"expect_tuple_filters,omitempty"`
AssertWritesCoveredByFilter bool `yaml:"assert_writes_covered_by_filter,omitempty"`
}
TestCase represents an embedded test case defined in the mapping file.
type Tuple ¶
type Tuple struct {
User string `yaml:"user" json:"user"`
Relation string `yaml:"relation" json:"relation"`
Object string `yaml:"object" json:"object"`
Action TupleAction `yaml:"action,omitempty" json:"action,omitempty"`
Condition string `yaml:"condition,omitempty" json:"condition,omitempty"` // FGA condition name
Context map[string]any `yaml:"context,omitempty" json:"context,omitempty"` // rendered FGA context
}
Tuple is a resolved FGA relationship tuple. The mapper produces values of this type; the language owns the type because embedded test cases (TestCase) declare expected tuples, keeping the data model in a single leaf package.
type TupleAction ¶
type TupleAction string
TupleAction represents the action to perform on a tuple.
const ( ActionWrite TupleAction = "write" ActionDelete TupleAction = "delete" )
type TupleFilter ¶
type TupleFilter struct {
User string `json:"user,omitempty"`
Relation string `json:"relation,omitempty"`
Object string `json:"object,omitempty"`
Action TupleFilterAction `json:"action"`
}
TupleFilter is a rendered tuple filter produced by the mapper. Empty fields act as wildcards that match any value in the corresponding FGA Read API field.
type TupleFilterAction ¶
type TupleFilterAction string
TupleFilterAction represents the action for a tuple filter. Semantically distinct from TupleAction: patch/delete operate on FGA read results, not individual tuples.
const ( FilterActionPatch TupleFilterAction = "patch" FilterActionDelete TupleFilterAction = "delete" )
type ValidateOption ¶
type ValidateOption func(*validateConfig)
ValidateOption configures a Validate call.
func WithMaxRules ¶
func WithMaxRules(n int) ValidateOption
WithMaxRules overrides the default cap on the number of rules per mapping file. A non-positive value is ignored and the default is retained.
Note: the identically-named mapper.WithMaxRules instead treats a non-positive value as a configuration error surfaced from Compile, rather than a no-op.
type ValidationError ¶
ValidationError represents a validation error in the mapping configuration.
func (*ValidationError) Error ¶
func (e *ValidationError) Error() string