Repository navigation
Extend schema loader validation to use schema reference defined in #431 #459
Copy link
Copy link
Open
Labels
willowReleased in WillowReleased in Willow
Description
Activity
Implementation sketch
Blocked on #431 (ships the JSON Schema contract). Once merged, the plan is to make JSON Schema own the per-file structural pass while the Python validator keeps only the cross-file/semantic checks.
Where it runs: in
SchemaValidator.validate_document, preserving the current "collect every issue, gate at the end" model rather than raising on first error in the loader. This keeps the existing_gate/SchemaValidationErroraggregation UX (one report listing all structural and semantic problems).Steps:
- Add
jsonschematorequirements/base.in(needs a version withDraft202012Validator, the contract's draft); confirm the JSON file ships as package data. - Carry the raw parsed mapping alongside the typed object — add a
raw: dictfield toSchemaDocument, populated by the loader — since JSON Schema validates the raw dict, not the coerced dataclass. - Load the schema once (cached) into a
Draft202012Validator; map eachiter_errors(document.raw)result to aValidationIssue(ERROR, …), foldingerror.json_pathinto the message so operators see the offending field. - Replace the hand-rolled structural checks in
validate_document(identifier patterns, required fields, empty-scope,schema_versionconst, permission-id shape,additionalProperties) with the JSON Schema pass. Keep only what the contract can't express — the Paragon icon-name membership check (schema enforcesminLength:1, not the vendored name set). - Leave
validate_setandvalidate_compileduntouched — those are the cross-file/compile-time semantic checks the compiler owns.
Notes:
- Loader still hard-fails (
SchemaLoadError) on un-parseable YAML / non-mapping top level, before structural validation can run. - The Casbin-prefix identifier rejection likely becomes redundant (the
identifierpattern already excludes^) — verify and drop. - Top-level
anyOfandrole_extension.anyOfyield opaque jsonschema messages; add light message cleanup for those two. - Tests: move structural cases to assert the JSON Schema pass rejects them; add a drift guard that every canonical
.yamlfixture validates against the vendored contract.
- Add
Metadata
Metadata
Assignees
Labels
willowReleased in WillowReleased in Willow
Type
Projects
- StatusShow more project fieldsReady for Development
Current loader implementation (#446) does basic, python-based yaml validation when loading the policy schemas.
Now that the schema shape is defined with a jsonschema compliant file in #431, we can use the jsonschema library to validate each document against it directly as the per-file structural pass, then keep our Python validator only for the cross-file/semantic checks the compiler owns. That guarantees we never drift from the published spec.