Skip to content

feat: cel supported operators - #6027

Merged
wolf4ood merged 1 commit into
eclipse-edc:mainfrom
wolf4ood:feat/cel_supported_operators
Sep 25, 2026
Merged

wolf4ood merged 1 commit into
eclipse-edc:mainfrom
wolf4ood:feat/cel_supported_operators

Conversation

@wolf4ood

@wolf4ood wolf4ood commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

What this PR changes/adds

Adds an optional supportedOperators field to CEL expressions. It limits which constraint operators an expression is invoked with.

  • Empty (default): behavior is unchanged. The expression runs whenever its left operand matches.
  • Non-empty: at runtime, an expression runs only when the constraint's operator is in the list. If no expression registered for a left operand supports the operator, the constraint is denied.
  • Policy validation: creating or updating a policy definition fails if a constraint uses an operator that no CEL expression for its left operand supports.

Operators use the enum names, e.g. "EQ" or "IS_PART_OF". The deprecated IN is treated as IS_PART_OF.

CEL expressions can also use a new binding, this.odrlOperator. It holds the ODRL operator name without the namespace ("eq", "isPartOf", …), next to the existing this.operator, which holds the enum name. Expressions can use the same names policy authors write in ODRL, and IN/IS_PART_OF both show up as "isPartOf". Example:

this.odrlOperator == 'eq' ? ctx.x == this.rightOperand : ctx.x in this.rightOperand

Also:

  • Adds the new field to the model, the management context, the v5 JSON schema, the transformers and the SQL store. The store adds a supported_operators column, with ADD COLUMN IF NOT EXISTS for existing tables.
  • PolicyValidator now reports each validation failure only once. Before, a function registered in several policy contexts reported the same failure once per context.

Why it does that

Briefly state why the change was necessary.

Further notes

List other areas of code that have changed but are not necessarily linked to the main feature. This could be method
signature changes, package declarations, bugs that were encountered and were fixed inline, etc.

Who will sponsor this feature?

Please @-mention the committer that will sponsor your feature.

Linked Issue(s)

Closes #6023

Please be sure to take a look at the contributing guidelines and our etiquette for pull requests.

@wolf4ood wolf4ood self-assigned this Sep 25, 2026
@wolf4ood wolf4ood added the enhancement New feature or request label Sep 25, 2026
@wolf4ood
wolf4ood force-pushed the feat/cel_supported_operators branch from 39921d8 to cb0aa28 Compare September 25, 2026 09:40
@wolf4ood wolf4ood changed the title Feat/cel supported operators feat: cel supported operators Sep 25, 2026
@wolf4ood
wolf4ood force-pushed the feat/cel_supported_operators branch from cb0aa28 to 63677bb Compare September 25, 2026 09:44
@wolf4ood
wolf4ood force-pushed the feat/cel_supported_operators branch from 63677bb to d33eb98 Compare September 25, 2026 09:45
@wolf4ood
wolf4ood marked this pull request as ready for review September 25, 2026 10:14
@wolf4ood
wolf4ood requested a review from a team as a code owner September 25, 2026 10:14
@wolf4ood
wolf4ood merged commit 393baa2 into eclipse-edc:main Sep 25, 2026
32 of 33 checks passed
@wolf4ood
wolf4ood deleted the feat/cel_supported_operators branch September 25, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add supportedOperators in cel expression

2 participants