Repository navigation
refactor: loosen operation_context to a key allowlist + safe-value validation - #209
Open
arorashivam96 wants to merge 2 commits into
Open
arorashivam96 wants to merge 2 commits into
arorashivam96 wants to merge 2 commits into
Conversation
OperationContext now accepts an optional IDE-surface suffix on the agent value, written as agent/<host> (e.g. codex/jetbrains), drawn from a new closed host allowlist (jetbrains, vscode, cli). The agent value is split on '/': the base is validated against the agent allowlist and the optional suffix against the host allowlist; unknown bases and unknown suffixes are still rejected. Enables plugin/tool attribution to record the IDE surface while preserving the closed key/value allowlist model. Bumped 1.0.1 -> 1.1.0.
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The new changelog release lacks an accurate comparison reference and leaves the Unreleased link stale.
1 open finding
What changed in this PR
Adds optional allowlisted host suffixes to OperationContext agent values.
Changes:
- Validates agent bases and optional host suffixes separately.
- Adds validation tests.
- Bumps version to 1.1.0 and updates the changelog.
| File | Description |
|---|---|
src/PowerPlatform/Dataverse/core/config.py |
Adds host-suffix validation. |
tests/unit/test_operation_context.py |
Tests accepted and rejected suffixes. |
pyproject.toml |
Bumps package version. |
CHANGELOG.md |
Documents the feature release. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), | ||
| and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). | ||
|
|
||
| ## [1.1.0] - 2026-08-24 |
Drop the closed skill/agent/host value allowlists. New agents and skills are added constantly, so enumerating values forces an SDK release for every addition and the enums had already drifted. The validator now enforces the key allowlist (app/skill/agent), the safe-character pattern (still excludes spaces/control chars/PII), and the app <name>/<version> format. Any safe-charset agent/skill value is accepted, including an agent/<surface> suffix like codex/jetbrains. Unknown keys and unsafe characters are still rejected.
Comment on lines
+75
to
+77
| # Key allowlist + safe-value validation. Values are not enumerated (new | ||
| # agents/skills are added constantly); the _CONTEXT_PATTERN charset above | ||
| # already guards against spaces/control characters/PII. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What
Loosens
OperationContextvalidation:skillandagentvalues are no longer checked against closed allowlists. The validator now enforces only:app,skill,agent(unknown keys rejected)-,_,.,/(still excludes spaces, control characters, and the punctuation PII such as emails would need)<name>/<version>format guardWhy
New agents and skills are added constantly. Enumerating their values server-side means every new agent or skill forces an SDK release before it can be attributed — and the enums had already drifted out of sync with the plugin (
_ALLOWED_SKILLSwas missingerp-xpp/dv-overview;_ALLOWED_AGENTSwas missinggemini-cli/antigravity-cli). Validating the key is present and the value is safe keeps the PII/injection protection that matters, without the maintenance treadmill. This also means anagent/<surface>suffix likecodex/jetbrains(used for JetBrains attribution in the companiondataverse-skillsPR) is accepted with no further SDK change.Change
OperationContext.__post_init__drops_ALLOWED_SKILLS,_ALLOWED_AGENTS,_ALLOWED_HOSTSand their per-value checks. Key allowlist, safe-character regex, and app-format guard are unchanged.Backward compatible: every string that was valid before is still valid. Only previously-rejected shapes (an unenumerated agent/skill, or an
agent/<surface>suffix) now pass. Unknown keys, spaces, control characters, and emails are still rejected.Tests
tests/unit/test_operation_context.py:test_reject_unknown_skill/test_reject_unknown_agent(and the earlier host-suffix reject tests) withtest_accepts_any_safe_skill_valueandtest_accepts_any_safe_agent_value(coveringerp-xpp, future skills,gemini-cli, future agents, andcodex/jetbrains).pytest tests/unit/test_operation_context.py— 25 passed.Version
1.0.1 → 1.1.0, changelog updated.