fix(sdk): read the TDF spec version from all three places - #411
pflynn-virtru wants to merge 3 commits into
Conversation
Adds failing tests for a manifest whose spec version is recorded under the non-aligned tdf_spec_version name (at the root or under payload), for null and non-string values, for precedence, and for the writer emitting schemaVersion only. Also covers files whose digest encoding disagrees with what the version field implies, and that tampering is still caught in each case. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Paul Flynn <pflynn-virtru@users.noreply.github.com>
…rusting it Manifest parsing now resolves the spec version in precedence order: schemaVersion, then tdf_spec_version at the manifest root, then tdf_spec_version under payload. Only non-empty JSON strings count; null and other non-string values are skipped without failing the decode. The writer is unchanged and emits schemaVersion only, so a round trip normalizes the non-aligned name. The reader no longer uses the version to choose between raw and hex integrity digests. It computes the raw digest and accepts the recorded value if it is base64 of either the raw bytes or their hex, for segment hashes and the root signature; for assertion signatures both aggregateHash||hash candidates are built. The version field is unauthenticated and only tracked the encoding because this SDK's writer set both from one boolean. Hex is an invertible encoding of the same HMAC, so accepting both weakens nothing. Counterpart of opentdf/platform#4060. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Paul Flynn <pflynn-virtru@users.noreply.github.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughManifest deserialization now falls back to non-empty ChangesManifest version compatibility
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change lets the SDK read the spec version from additional manifest locations while still writing the canonical field. No merge-blocking issue was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The compatibility change preserves existing integrity checks and canonical output. No introduced verification bypass was identified. The risk remains bounded, but this assessment does not establish the security of every supported payload mode or deployment. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit reads the version line, Comment |
… as-is Drop the change that accepted either digest encoding regardless of the recorded version. This PR now only widens where the version is read from: root schemaVersion, then root tdf_spec_version, then payload.tdf_spec_version. The resolved version still selects hex vs raw digests, as before. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Paul Flynn <pflynn-virtru@users.noreply.github.com>
X-Test Failure Report |
|
|
@coderabbitai review |
|



Some TDF files record their spec version as
tdf_spec_versioninstead ofschemaVersion, either at the manifest root or underpayload. This SDK only readsschemaVersion, so those files are read as legacy (hex digests) and fail to decrypt.Change: read the version from
schemaVersion, then roottdf_spec_version, thenpayload.tdf_spec_version. Non-string values likenullare skipped. The writer still emitsschemaVersiononly.Reader-only, backwards compatible. Counterparts: opentdf/platform#4060 (Go), opentdf/web-sdk#1054.
Testing: unit tests for each placement and precedence; end-to-end decrypt with the version under each name.
mvn verifypasses.🤖 Generated with Claude Code
Summary by CodeRabbit
schemaVersionwhen present.schemaVersionfield.