Rule Cascade
LearnSeverities and resolutions

Acknowledge a warning

A warning that blocks until the user confirms it.

A warning with acknowledgement: required blocks the request until the user confirms it. The finding says resolution: acknowledge. The next request carries a resolution for the rule, and the finding becomes acknowledged and stops blocking. The default is acknowledgement: none.

Syntax

a warning that needs an acknowledgement
- id: <rule id>
  kind: validation
  severity: warning
  acknowledgement: required
  # ...
the next request carries a resolution
"resolutions": [ { "rule": "<rule id>", "type": "acknowledge" } ]

Example

150 items is more than the limit of 100. The warning blocks, because it needs an acknowledgement.

acknowledgement.ruleset.yaml
ruleCascade: 1.0.0
kind: RuleSet
metadata: { id: learn.acknowledgement, version: 1.0.0, title: "Acknowledgement" }
scope:
  - { level: organization, id: learn }
entities:
  Order:
    schema: { $ref: "./learn.openapi.yaml#/components/schemas/Order" }
rules:
  - id: order.quantity.large
    kind: validation
    target: { entity: Order, field: /quantity }
    operations: [create]
    assert: { op: lte, args: [{ var: data.quantity }, 100] }
    severity: warning
    acknowledgement: required
    finding: { code: LRN-ACK-001, message: order.largeQuantity, args: { limit: 100 } }
messages:
  en:
    order.largeQuantity: "More than {limit} items. Please confirm the quantity."
tests:
  - name: a large order waits for an acknowledgement
    entity: Order
    operation: create
    given:
      data: { quantity: 150 }
    expect:
      decision: deny
      findings:
        - { rule: order.quantity.large, blocking: true, status: open }
  - name: the acknowledged warning no longer blocks
    entity: Order
    operation: create
    given:
      data: { quantity: 150 }
      resolutions:
        - { rule: order.quantity.large, type: acknowledge }
    expect:
      decision: allow
      findings:
        - { rule: order.quantity.large, blocking: false, status: acknowledged }
  - name: a small order has no finding
    entity: Order
    operation: create
    given:
      data: { quantity: 100 }
    expect: { decision: allow, findings: [] }
request.json
{
  "entity": "Order",
  "operation": "create",
  "data": {
    "quantity": 150
  }
}

Result, from the engine

Decisiondeny1 finding, server channel

  • LRN-ACK-001warningblockingMore than 100 items. Please confirm the quantity./quantity
Try it YourselfOpens this ruleset and request in the playground. Nothing to install.

The same request with a resolution for the rule. The finding is still reported, but it is acknowledged and does not block.

acknowledgement-resolved.ruleset.yaml
ruleCascade: 1.0.0
kind: RuleSet
metadata: { id: learn.acknowledgement, version: 1.0.0, title: "Acknowledgement" }
scope:
  - { level: organization, id: learn }
entities:
  Order:
    schema: { $ref: "./learn.openapi.yaml#/components/schemas/Order" }
rules:
  - id: order.quantity.large
    kind: validation
    target: { entity: Order, field: /quantity }
    operations: [create]
    assert: { op: lte, args: [{ var: data.quantity }, 100] }
    severity: warning
    acknowledgement: required
    finding: { code: LRN-ACK-001, message: order.largeQuantity, args: { limit: 100 } }
messages:
  en:
    order.largeQuantity: "More than {limit} items. Please confirm the quantity."
tests:
  - name: the acknowledged warning no longer blocks
    entity: Order
    operation: create
    given:
      data: { quantity: 150 }
      resolutions:
        - { rule: order.quantity.large, type: acknowledge }
    expect:
      decision: allow
      findings:
        - { rule: order.quantity.large, blocking: false, status: acknowledged }
  - name: a large order waits for an acknowledgement
    entity: Order
    operation: create
    given:
      data: { quantity: 150 }
    expect:
      decision: deny
      findings:
        - { rule: order.quantity.large, blocking: true, status: open }
  - name: a small order has no finding
    entity: Order
    operation: create
    given:
      data: { quantity: 100 }
    expect: { decision: allow, findings: [] }
request.json
{
  "entity": "Order",
  "operation": "create",
  "data": {
    "quantity": 150
  },
  "resolutions": [
    {
      "rule": "order.quantity.large",
      "type": "acknowledge"
    }
  ]
}

Result, from the engine

Decisionallow1 finding, server channel

  • LRN-ACK-001warningnot blocking, acknowledgedMore than 100 items. Please confirm the quantity./quantity
Try it YourselfOpens this ruleset and request in the playground. Nothing to install.

Common mistakes

  • acknowledgement: required on an info or error rule. Only a warning can be acknowledged; the ruleset does not load (SCHEMA_INVALID).
  • Trusting the client. The server evaluates again with the resolutions the user sent; a resolution only counts for the rule it names.

Exercise

Lower the limit to 50 items and keep the acknowledgement. Keep a test that is denied, a test with a resolution that is allowed, and a test for a small order.

Hint

Change both 100s to 50, then change the quantities in the tests.

Show answer
acknowledgement.ruleset.yaml
ruleCascade: 1.0.0
kind: RuleSet
metadata: { id: learn.acknowledgement, version: 1.0.0, title: "Acknowledgement" }
scope:
  - { level: organization, id: learn }
entities:
  Order:
    schema: { $ref: "./learn.openapi.yaml#/components/schemas/Order" }
rules:
  - id: order.quantity.large
    kind: validation
    target: { entity: Order, field: /quantity }
    operations: [create]
    assert: { op: lte, args: [{ var: data.quantity }, 50] }
    severity: warning
    acknowledgement: required
    finding: { code: LRN-ACK-001, message: order.largeQuantity, args: { limit: 50 } }
messages:
  en:
    order.largeQuantity: "More than {limit} items. Please confirm the quantity."
tests:
  - name: a large order waits for an acknowledgement
    entity: Order
    operation: create
    given:
      data: { quantity: 100 }
    expect:
      decision: deny
      findings:
        - { rule: order.quantity.large, blocking: true, status: open }
  - name: the acknowledged warning no longer blocks
    entity: Order
    operation: create
    given:
      data: { quantity: 100 }
      resolutions:
        - { rule: order.quantity.large, type: acknowledge }
    expect:
      decision: allow
      findings:
        - { rule: order.quantity.large, blocking: false, status: acknowledged }
  - name: a small order has no finding
    entity: Order
    operation: create
    given:
      data: { quantity: 50 }
    expect: { decision: allow, findings: [] }
request.json
{
  "entity": "Order",
  "operation": "create",
  "data": {
    "quantity": 100
  }
}

Result, from the engine

Decisiondeny1 finding, server channel

  • LRN-ACK-001warningblockingMore than 50 items. Please confirm the quantity./quantity
Course overview

On this page