Skip to content

Feature flags, FGA and Pipes leases - #3

Merged
sylvesterdamgaard merged 3 commits into
mainfrom
feat/wave-10-sdk
Oct 10, 2026
Merged

sylvesterdamgaard merged 3 commits into
mainfrom
feat/wave-10-sdk

Conversation

@sylvesterdamgaard

@sylvesterdamgaard sylvesterdamgaard commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Adds SDK support for the Cbox ID wave-10 features (laravel-id 1.24).

Feature flags

  • feature_flags(source) / has_feature(source, key), CboxUser.feature_flags and CboxUser.has_feature(key) (None = scope not requested, [] = nothing on). FEATURE_FLAGS_SCOPE.
  • env.feature_flags.evaluate({"user_id": ..., "organization_id": ...}) via the regenerated management client.

Fine-grained authorization

  • Regenerated env.fga: check, check_batch (sent as checks[]=), tuples.write/delete/list, resources.list, subjects.list, schema.get/update/validate, with consistency_token on the reads.
  • fga_tuple() writes the document:readme#viewer@user:alice notation from the same mapping tuples.write takes.
  • Generator: an action whose own answer is 202 Accepted (directories.sync) is documented as oneOf its body and the approval body; the generator reads the non-approval branch, so env.directories.sync() returns the directory.

Pipes

  • client.pipes.lease_token(provider, user_id=..., purpose=...) with a client-credentials vault.lease token the client obtains and caches until shortly before expiry. PipesClient(issuer, access_token) for a token you already hold (e.g. one issued for the person).
  • Typed refusals under PipeLeaseError: PipeNotConnectedError / PipeReauthorizationRequiredError with connect_url and connect_url_with(client_id=, return_to=), PipeTemporarilyUnavailableError with retry_after, PipeLeaseDeniedError.
  • client.pipe_connect_url(provider, return_to) and pipe_connect_url() for the hosted connect page.

The Python FrontendClient does not wrap the embedded sign-in calls, so there is no SMS-factor surface to add here.

Vendored openapi/account.yaml and openapi/environment.yaml are copied from cbox-id wave-10 (6b373319, where the batch check is its own action, fga.check_batch); the surface snapshot only gains lines.

Gate: ruff check ., ruff format --check ., mypy (strict), pytest (235 passed), python -m scripts.generate_management --check.

- feature_flags()/has_feature() and CboxUser.feature_flags / has_feature() from the
  feature_flags claim; FEATURE_FLAGS_SCOPE.
- Management clients regenerated from the wave-10 specs (feature flag evaluation, FGA,
  pipes, radar, SMS settings, HRIS directories). The generator folds an action that is
  also a namespace (fga.check.batch -> fga.check_batch). fga_tuple() for the batch notation.
- client.pipes.lease_token() / PipesClient with typed refusals carrying connect_url and
  retry_after; pipe_connect_url() and CboxIdClient.pipe_connect_url().
The batch check is its own action now, so the generator's namespace folding is gone.
An action whose own answer is 202 documents it as oneOf its body and the approval body;
the generator reads that branch, so directories.sync returns its Directory.
…r organization

- Vendored environment spec from cbox-id main (aa419d1b): environment sign-in methods
  (signin.social update/enable/disable/inherit/offered), branding appearance with data-URI
  logo and favicon.
- FrontendClient.config(organization=...) and FrontendConfig.methods.
- 0.11.0 in pyproject.toml and the changelog.
@sylvesterdamgaard
sylvesterdamgaard merged commit fa058d1 into main Oct 10, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant