Skip to content

feat(plan): add --only filter for bola/bfla/baseline - #21

Open
jabrailkhalil wants to merge 2 commits into
ScalerOpenSourceLabsOrg:mainfrom
jabrailkhalil:feat/only-flag
Open

jabrailkhalil wants to merge 2 commits into
ScalerOpenSourceLabsOrg:mainfrom
jabrailkhalil:feat/only-flag

Conversation

@jabrailkhalil

Copy link
Copy Markdown

What & why

Adds the --only <kind> CLI flag so a scan can be restricted to a single test family: bola, bfla, or baseline. This is useful when only one class of checks is needed (e.g. baseline-only self-access validation during setup).

Closes #8

Type of change

  • Bug fix
  • New feature
  • Docs
  • Refactor / chore
  • Breaking change

What changed

  • src/engine/plan.ts: PlanOptions.only plus parseOnlyFilter() which validates the CLI value and raises a clear error listing the allowed kinds.
  • src/cli.ts: new --only <kind> option wired into the scan.
  • src/engine/run.ts: passes only through to the planner.
  • tests/plan.test.ts: coverage for the filter (plan only ever contains the requested kind) and for the invalid-value error.
  • README flag table and CHANGELOG updated.

Checklist

  • npm test passes (26 tests, was 23)
  • npm run typecheck passes
  • npm run build passes
  • Added/updated tests for the change (no network except the bundled mock server)
  • Updated docs (README / CHANGELOG) if behavior or flags changed
  • Follows the project principles: no fabricated identifiers/ownership, and mutations stay behind --include-unsafe
  • Commits follow Conventional Commits

Output

$ npm run dev -- scan --spec examples/petstore-openapi.yaml --config examples/identities.yaml --dry-run --only bogus
Error: Invalid value for --only: "bogus". Allowed values: bola, bfla, baseline.   (exit 2)

$ npm run dev -- scan --spec examples/petstore-openapi.yaml --config examples/identities.yaml --dry-run --only bola
... only BOLA rows in the report ...

Notes for reviewers

The option is opt-in and changes nothing when omitted, so the default scan behaviour is preserved.

@jabrailkhalil
jabrailkhalil requested a review from a team as a code owner September 10, 2026 17:25
@jabrailkhalil

Copy link
Copy Markdown
Author

The CI workflows for the current head ca0468d346 are waiting for contributor workflow approval (action_required): CI. Could a maintainer approve the pending runs when convenient? These runs have not executed their checks yet; I will address any failures once they run.

@kunalKumar-13 kunalKumar-13 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good, tests pass and typecheck is clean. one small thing below: constructor and __proto__ get past the lookup because it reads inherited keys, so --only constructor runs an empty plan instead of showing the error.

Comment thread src/engine/plan.ts Outdated
*/
export function parseOnlyFilter(value: string | undefined): TestKind | undefined {
if (value === undefined) return undefined;
const kind = ONLY_FILTERS[value.toLowerCase()];

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ONLY_FILTERS['constructor'] is Object, so this returns a function instead of throwing. an own-property check fixes it:

Suggested change
const kind = ONLY_FILTERS[value.toLowerCase()];
const key = value.toLowerCase();
const kind = Object.hasOwn(ONLY_FILTERS, key) ? ONLY_FILTERS[key] : undefined;

@jabrailkhalil jabrailkhalil Sep 29, 2026 •

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 45e179b with the own-property check you suggested. Added regression cases for constructor, proto, and uppercase CONSTRUCTOR: all three failed before the fix and now pass. All 29 tests, typecheck, and build pass. The built CLI now exits 2 with the allowed-value error for those inputs; bola/BFLA/Baseline still produce nonempty dry-run plans and exit 0. The new CI run is awaiting maintainer approval before execution: https://github.com/ScalerOpenSourceLabsOrg/authzprobe/actions/runs/36575485610. Could you approve that run?

@kunalKumar-13 kunalKumar-13 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

checked 45e179b. constructor, proto and CONSTRUCTOR now exit 2 with the error, and bola/bfla/baseline still plan and exit 0. 29/29, typecheck and build clean. approved the ci run too.

@jabrailkhalil

Copy link
Copy Markdown
Author

Thanks @kunalKumar-13 for checking the inherited-key fix and approving CI. I confirmed the reviewed head 45e179b22d8a now has passing Node 18/20/22 checks and the end-to-end demo, with approval and no merge conflicts. From my side this is ready to merge when convenient; no further code changes are needed for the review feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a --only <kind> filter (bola/bfla/baseline)

2 participants