feat: add match_all support to network-acl commands - #1643
Open
bkiran6398 wants to merge 4 commits into
Open
Conversation
- Update github.com/auth0/go-auth0 from v1.48.0 to v1.48.1-0.20260904094659-f5a492879bcb to pull in unreleased changes needed for match-all network ACL support. - Sync go.sum accordingly.
- Add the rule.match_all field to network-acl create and update, exposed via --rule JSON and a new --match-all flag. - Confirm Match All before the match/not_match prompt in the interactive builder and short-circuit rule construction when set, reflecting that match_all is a top-level signal mutually exclusive with match/not_match. - Render a MATCH ALL row in the show/create/update output. - Extend extractCurrentRuleDefaults to pre-fill match_all on update. - Add unit tests for rule building, defaults extraction, and display, plus an integration case for a match_all deny-all rule. - Regenerate command docs for the new flag and examples.
- Correct the asserted priority from 99 to 6 in the match_all deny-all integration case so it matches the value the create command sends.
bkiran6398
marked this pull request as ready for review
September 7, 2026 08:29
- Seed ruleInputs.MatchAll from the --match-all flag before AskBool in promptForRuleDetails; AskBool suppresses its own prompt when the flag is set explicitly, which previously left MatchAll false and pushed the user into the match/not_match flow instead of building a match_all rule. - Check the flag before the match-criteria prompts so it short-circuits the rest of the rule questions, matching how the other rule sub-config flags behave. - Add TestPromptForRuleDetails_MatchAllFlag to exercise the flag-to-input wiring, closing the gap where only buildNetworkACLRule and the --rule JSON path were covered.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #1643 +/- ##
==========================================
+ Coverage 60.60% 61.03% +0.42%
==========================================
Files 135 148 +13
Lines 26385 29177 +2792
==========================================
+ Hits 15991 17808 +1817
- Misses 9407 10209 +802
- Partials 987 1160 +173 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔧 Changes
Adds support for unconditional deny-all network ACL rules via the new
match_allrule signal.match_allonnetwork-acl createandnetwork-acl update, through--ruleJSON and a new--match-allflag.match_allis a top-level signal, mutually exclusive withmatch/not_match(the API rejects the combination), so it is asked on its own rather than as a match criterion.MATCH ALLrow in command output and pre-fills the value when updating an existing rule.📚 References
🔬 Testing
match_alldeny-all rule.match_all, and combining it withmatch/not_matchreturns the documented 400.📝 Checklist