Skip to content

feat: add match_all support to network-acl commands - #1643

Open
bkiran6398 wants to merge 4 commits into
mainfrom
DXCDT-2273/support-match-all-network-acl
Open

feat: add match_all support to network-acl commands#1643
bkiran6398 wants to merge 4 commits into
mainfrom
DXCDT-2273/support-match-all-network-acl

Conversation

@bkiran6398

@bkiran6398 bkiran6398 commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🔧 Changes

Adds support for unconditional deny-all network ACL rules via the new match_all rule signal.

  • Exposes match_all on network-acl create and network-acl update, through --rule JSON and a new --match-all flag.
  • In the interactive builder, confirms Match All before the match/not_match prompt and skips criteria selection when set. match_all is a top-level signal, mutually exclusive with match/not_match (the API rejects the combination), so it is asked on its own rather than as a match criterion.
  • Displays a MATCH ALL row in command output and pre-fills the value when updating an existing rule.
# Block all traffic for a scope
auth0 network-acl create --description "Deny All" --priority 99 --active true \
  --rule '{"action":{"block":true},"scope":"tenant","match_all":true}'

📚 References

🔬 Testing

  • Unit tests cover rule building, defaults extraction, and display rendering.
  • Adds an integration case creating a match_all deny-all rule.
  • Manually validated against a live tenant: create/update/read echo match_all, and combining it with match/not_match returns the documented 400.

📝 Checklist

  • All new/changed/fixed functionality is covered by tests (or N/A)
  • I have added documentation for all new/changed functionality (or N/A)

- Update github.com/auth0/go-auth0 from v1.48.0 to
  v1.48.1-0.20260904094659-f5a492879bcb to pull in unreleased
  changes needed for match-all network ACL support.
- Sync go.sum accordingly.
- Add the rule.match_all field to network-acl create and update, exposed
  via --rule JSON and a new --match-all flag.
- Confirm Match All before the match/not_match prompt in the interactive
  builder and short-circuit rule construction when set, reflecting that
  match_all is a top-level signal mutually exclusive with match/not_match.
- Render a MATCH ALL row in the show/create/update output.
- Extend extractCurrentRuleDefaults to pre-fill match_all on update.
- Add unit tests for rule building, defaults extraction, and display, plus
  an integration case for a match_all deny-all rule.
- Regenerate command docs for the new flag and examples.
@bkiran6398 bkiran6398 changed the title feat: add unconditional deny all to Tenant ACL feat: add match_all support to network-acl commands Sep 4, 2026
- Correct the asserted priority from 99 to 6 in the match_all deny-all
  integration case so it matches the value the create command sends.
@bkiran6398
bkiran6398 marked this pull request as ready for review September 7, 2026 08:29
@bkiran6398
bkiran6398 requested a review from a team as a code owner September 7, 2026 08:29
- Seed ruleInputs.MatchAll from the --match-all flag before AskBool in
  promptForRuleDetails; AskBool suppresses its own prompt when the flag is
  set explicitly, which previously left MatchAll false and pushed the user
  into the match/not_match flow instead of building a match_all rule.
- Check the flag before the match-criteria prompts so it short-circuits the
  rest of the rule questions, matching how the other rule sub-config flags
  behave.
- Add TestPromptForRuleDetails_MatchAllFlag to exercise the flag-to-input
  wiring, closing the gap where only buildNetworkACLRule and the --rule JSON
  path were covered.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant