api7 / api7/lua-resty-saml

Unify the three OneTimeUse diagnostics

Open
#57 1 comment 0 reactions 1 assignee View on GitHub

@shreemaan-abhishek is already working on this.

Since Aug 31, 2026.

Dominant language
Perl
Stars
2
Forks
3
Avg merge
2d 20h
Merged PRs (30d)
3

Description

What

PR #53 leaves the OneTimeUse-and-the-record concept voiced three ways within ~220 lines of lua/resty/saml.lua:

  • the no-dict case: a dedicated ngx.log(ngx.WARN, ...) in assertions_acceptable
  • the record-will-lapse case: a structured buffer in spend_assertions flushed after the loop
  • the full-dict case: a ternary suffix on the no-memory ERR

They share neither wording nor fields, and four anchored test regexes pin three templates, so a cross-cutting change to how the SP names an assertion in these lines has to be made three times in three syntactic forms, and nothing catches the three drifting apart.

Each shape is load-bearing where it stands (the no-dict warn fires where the config gap is known, the lapse warn defers for the rollback, the full-dict line rides the ERR because it is the same failed add), so unification is a design task rather than a find-replace: a shared formatter over {id, issuer, zone?, outcome} that each site feeds, or a decision that three shapes are the accepted cost.

Raised by @jarvis9443 reviewing #53 (r3894613411).

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.