Skip to content

Extend schema loader validation to use schema reference defined in #431 #459

Description

@rodmgwgu

Current loader implementation (#446) does basic, python-based yaml validation when loading the policy schemas.

Now that the schema shape is defined with a jsonschema compliant file in #431, we can use the jsonschema library to validate each document against it directly as the per-file structural pass, then keep our Python validator only for the cross-file/semantic checks the compiler owns. That guarantees we never drift from the published spec.

Activity

  1. rodmgwgu commented on Sep 23, 2026

    @rodmgwgu
    ContributorAuthor

    Implementation sketch

    Blocked on #431 (ships the JSON Schema contract). Once merged, the plan is to make JSON Schema own the per-file structural pass while the Python validator keeps only the cross-file/semantic checks.

    Where it runs: in SchemaValidator.validate_document, preserving the current "collect every issue, gate at the end" model rather than raising on first error in the loader. This keeps the existing _gate / SchemaValidationError aggregation UX (one report listing all structural and semantic problems).

    Steps:

    1. Add jsonschema to requirements/base.in (needs a version with Draft202012Validator, the contract's draft); confirm the JSON file ships as package data.
    2. Carry the raw parsed mapping alongside the typed object — add a raw: dict field to SchemaDocument, populated by the loader — since JSON Schema validates the raw dict, not the coerced dataclass.
    3. Load the schema once (cached) into a Draft202012Validator; map each iter_errors(document.raw) result to a ValidationIssue(ERROR, …), folding error.json_path into the message so operators see the offending field.
    4. Replace the hand-rolled structural checks in validate_document (identifier patterns, required fields, empty-scope, schema_version const, permission-id shape, additionalProperties) with the JSON Schema pass. Keep only what the contract can't express — the Paragon icon-name membership check (schema enforces minLength:1, not the vendored name set).
    5. Leave validate_set and validate_compiled untouched — those are the cross-file/compile-time semantic checks the compiler owns.

    Notes:

    • Loader still hard-fails (SchemaLoadError) on un-parseable YAML / non-mapping top level, before structural validation can run.
    • The Casbin-prefix identifier rejection likely becomes redundant (the identifier pattern already excludes ^) — verify and drop.
    • Top-level anyOf and role_extension.anyOf yield opaque jsonschema messages; add light message cleanup for those two.
    • Tests: move structural cases to assert the JSON Schema pass rejects them; add a drift guard that every canonical .yaml fixture validates against the vendored contract.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

willowReleased in Willow

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions