Skip to content

auth/codegen: multi-role required_roles emits compilable require_any_role guard (conformance T1) - #310

Merged
Sorcecoder merged 2 commits into
mainfrom
fix/t1-multirole-guard
Sep 1, 2026
Merged

Sorcecoder merged 2 commits into
mainfrom
fix/t1-multirole-guard

Conversation

@Sorcecoder

Copy link
Copy Markdown
Contributor

Docs↔codegen conformance sweep — code-wrong bucket. A multi-element required_roles (accepted by check) made guard_comment emit an uncompilable single-role call (require_role(&_user.0.role, "admin", "editor")), steering an agent to either a compile error or silently dropping roles (narrowing auth). Adds a free require_any_role(actual, &[&str]) to jerrycan-auth (mirrors the existing Tenant::require_any_role), and guard_comment emits the any-of form when >1 role. Single-role output is byte-identical (585 genroute tests + explicit string-equality assertions). No version bump.

Sorcecoder and others added 2 commits September 1, 2026 19:04
…quired_roles (T1)

A multi-role required_roles (e.g. ["admin","editor"]) interpolated into the
single-role guidance produced an uncompilable 2-arg require_role/_tenant.require_role
call; an agent then narrows authorization to the first role. Add a free
require_any_role(actual, allowed) to jerrycan-auth (mirroring Tenant::require_any_role)
and, in genroute::guard_comment, emit the any-of form when required_roles.len() > 1.
Single-role output is byte-identical.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant