Skip to content

docs: condition-set hierarchy and opt-in deletion in env copy - #671

Open
CarlosMion wants to merge 3 commits into
masterfrom
carlos/per-15750-copy-env-condition-set-hierarchy
Open

CarlosMion wants to merge 3 commits into
masterfrom
carlos/per-15750-copy-env-condition-set-hierarchy

Conversation

@CarlosMion

@CarlosMion CarlosMion commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Documents the environment-copy behaviour changed by https://github.com/permitio/permit-backend/pull/3387
    (PER-15750): condition-set hierarchy, an opt-in delete_target_only_condition_sets, exact scope matching, and
    per-object Policy Guard checks on a copy.
  • Merge after permit-backend#3387 is deployed to production. Until then this page describes behaviour the API
    doesn't have yet.

Changes

All changes are in docs/manage-your-account/creating-environments.mdx:

  • Copy rules: the extra permission the deletion option needs.
  • New "Copy into an environment protected by a Policy Guard" section:
    • every guarded object the copy would change or delete is checked as a direct API change would be, and a
      forbidden one fails the copy with 403;
    • unchanged and newly created objects don't need the guard's permission.
  • Copied objects checklist: "Condition Sets Inheritance" is now copied.
  • Conflict strategy table: overwrite also replaces a condition set's parent; neither strategy deletes
    target-only condition sets.
  • New "Condition set hierarchy in a copy" section:
    • a scope that copies a child but not its parent is refused with 409;
    • overwrite re-parents existing target sets;
    • a cyclic or mistyped source hierarchy is refused with 406.
  • Exclude or include objects: the old sentence said scope wildcards follow Unix filename matching. That was
    true only of custom_policies. It now states the real rules: * is the only wildcard, matching is
    case-sensitive, includes are ORed. The fnmatch note stays, scoped to custom_policies, which really uses it.
  • New "Delete condition sets the source doesn't have" section: the option with an example, which target sets
    it deletes, the cascade 409, the permission it needs, and that it has no effect on a new target.

No changelog entry: updates-and-feedback/changelog.mdx lists release sources rather than entries.

Test plan

  • cspell: no issues on the page.
  • Netlify deploy preview and redirect rules pass on the first commit; re-running for the new ones.
  • Prettier flags the page, but the master copy fails the same check (the page's tables use the repo's
    compact style), so I didn't reformat it.

🤖 Generated with Claude Code

Environment copy now keeps each condition set's parent (PER-15750,
permitio/permit-backend#3387). Document what that changes for API callers:
a scope that copies a child but not its parent is refused with 409,
overwrite re-parents existing target sets, a broken source hierarchy is
refused with 406, and the new delete_target_only_condition_sets option
with its matching rules, permission and policy-guard refusal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 00:16
@linear-code

linear-code Bot commented Oct 8, 2026

Copy link
Copy Markdown

PER-15750

@netlify

netlify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for permitio-docs ready!

Name Link
🔨 Latest commit 751f18f
🔍 Latest deploy log https://app.netlify.com/projects/permitio-docs/deploys/6ac7942ec5c28a0008908aef
😎 Deploy Preview https://deploy-preview-671--permitio-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

CarlosMion and others added 2 commits October 8, 2026 09:06
Scope patterns match case-sensitively with * as the only wildcard, and
include patterns are ORed (permitio/permit-backend#3387 makes the copy do
this; it used ILIKE and ANDed includes, and the page cited fnmatch).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…r object

permitio/permit-backend#3387 checks every guarded object a copy would change
or delete, as the API does for a direct change, instead of refusing only the
condition-set deletion option on a guarded target.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 13:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants