Skip to content

Regenerate protos from latest api (adds DeleteRelationships cursor) - #432

Merged
josephschorr merged 2 commits into
authzed:mainfrom
josephschorr:delete-relationships-cursor
Sep 14, 2026
Merged

josephschorr merged 2 commits into
authzed:mainfrom
josephschorr:delete-relationships-cursor

Conversation

@josephschorr

Copy link
Copy Markdown
Member

Summary

Regenerates the Go bindings from the latest buf.build/authzed/api, bumping the pinned reference in magefiles/gen.go from 55aa23d5 to ef1e3767.

The headline addition is the DeleteRelationships cursor (from authzed/api#174, merged):

  • DeleteRelationshipsRequest.OptionalCursor (field 6)
  • DeleteRelationshipsResponse.AfterResultCursor (field 4)

Together these enable resumable, cursor-advanced batched deletion on datastores that support it, mirroring the existing cursor fields on ReadRelationships and LookupResources.

The reference bump also picks up the accumulated documentation-only changes to the LookupResources and LookupSubjects streaming results ("results are not guaranteed to be unique") that landed in the API since the previous pin.

Details

  • magefiles/gen.go: BufTag 55aa23d5 → ef1e3767
  • Regenerated via mage gen:all
  • Only permission_service.*, proto/apidocs.swagger.json, and the zz_generated.version.go files change
  • go build ./... passes

@josephschorr
josephschorr requested a review from a team as a code owner September 10, 2026 22:51
"/v1/permissions/resources": {
"post": {
"summary": "LookupResources returns all the resources of a given type that a subject\ncan access whether via a computed permission or relation membership.",
"description": "Results are streamed and **not guaranteed to be unique**: the same resource\nmay be returned more than once (for example via caveated/conditional\nresults, or when a limit is set), possibly with differing permissionship.\nCallers that require uniqueness should deduplicate results.",

@miparnisari miparnisari Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Results are streamed and not guaranteed to be unique: the same resource\nmay be returned more than once (for example via caveated/conditional\nresults, or when a limit is set), possibly with differing permissionship

:wat:

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's from a different change but it is correct - you may get conditional (for caveated) vs approved (for the uncaveated branch)

miparnisari
miparnisari previously approved these changes Sep 10, 2026
Regenerates the Go bindings from the latest buf.build/authzed/api (BufTag
55aa23d5 -> ef1e3767, via mage gen:all), which adds optional_cursor to
DeleteRelationshipsRequest and after_result_cursor to
DeleteRelationshipsResponse for resumable, cursor-advanced batched deletion,
mirroring ReadRelationships and LookupResources. The reference bump also picks
up accumulated documentation-only changes to the LookupResources and
LookupSubjects streaming results.

Signed-off-by: Joseph Schorr <josephschorr@users.noreply.github.com>
@josephschorr
josephschorr force-pushed the delete-relationships-cursor branch 5 times, most recently from 7365886 to cc12308 Compare September 14, 2026 19:35
miparnisari
miparnisari previously approved these changes Sep 14, 2026
Resolves GO-2026-6061 (xDS RBAC / HTTP2 transport server vulnerabilities in
google.golang.org/grpc), the vulnerability govulncheck reports as affecting the
code, so that `mage lint:go` passes.

Signed-off-by: Joseph Schorr <josephschorr@users.noreply.github.com>
@josephschorr
josephschorr merged commit aa40325 into authzed:main Sep 14, 2026
10 of 11 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants