Skip to content

feat(authpolicy): request.* attribute mapping #156

Description

@maleck13

Parent: #130

Map Kuadrant request.* (the HTTP request) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Request attributes".

Note the namespace collision: Kuadrant request.* is the HTTP request; PPE request.* is trace metadata, HTTP data lives under http.*.

Approach: adapter input alias (Option 1) — present a request/http object from typed sources via the per-PDP input builder.

Acceptance (tiered testing — doc "Testing strategy"):

  • Request line + headers resolve for verbatim Kuadrant CEL/OPA v1 predicates; request.headers presented as a map.
  • Tier 1: Authorino reference JSON + expected decision checked in for every request.* attribute, Gap rows (protocol, size, body, raw_body) recorded as expected divergence.
  • Tier 2: ppe-pdp-diff cases run the unchanged predicates through the real resolver; cover the request.query/request.path query-carrying question and the flat-header-vs-map shape; unsupported attrs rejected at config time, not silently absent.
  • Tier 3: dual-gateway check for the transport-observable subset (real path/query/body capture).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions