- 
                Notifications
    You must be signed in to change notification settings 
- Fork 2
fix(sdk): add methods to examine Manifest and Policy #278
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
These capabilities were removed during a previous refactoring
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Summary of Changes
Hello @mkleene, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!
This pull request reintroduces and refines the SDK's ability to inspect TDF Manifest and Policy objects without requiring full decryption. It streamlines the internal API for manifest parsing by switching from Reader inputs to direct String inputs for JSON, and exposes these capabilities through new public methods in the SDK class, enhancing the SDK's utility for TDF content analysis.
Highlights
- Reintroduced SDK capabilities: Public methods SDK.readManifestandSDK.decodePolicyObjecthave been added to allow external examination of TDFManifestandPolicyobjects, restoring functionality previously removed during a refactoring.
- Manifest.readManifestsignature change: The internal- Manifest.readManifestmethod now directly accepts a- Stringcontaining the manifest JSON, simplifying its usage by removing the need for- Readerobjects.
- Internal API alignment: Manifest.readPolicyObjecthas been renamed toManifest.decodePolicyObjectand now accepts aManifestobject directly, aligning with the new approach of decoding from an already parsed manifest.
- Example and Tests: A new example (GetManifestInformation.java) demonstrates the usage of the new SDK methods, and comprehensive tests have been added/updated to ensure correctness and cover the new functionality.
Using Gemini Code Assist
The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.
Invoking Gemini
You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.
| Feature | Command | Description | 
|---|---|---|
| Code Review | /gemini review | Performs a code review for the current pull request in its current state. | 
| Pull Request Summary | /gemini summary | Provides a summary of the current pull request in its current state. | 
| Comment | @gemini-code-assist | Responds in comments when explicitly tagged, both in issue comments and review comments. | 
| Help | /gemini help | Displays a list of available commands. | 
Customization
To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.
Limitations & Feedback
Gemini Code Assist is currently in preview and may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments to provide feedback.
You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.
Footnotes
- 
Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩ 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request re-introduces methods to examine a TDF's manifest and policy, which were removed in a previous refactoring. It also refactors Manifest.readManifest to accept a String, which simplifies its usage. The changes are well-implemented and include a new example and tests. I've identified a couple of areas for improvement in the new example code regarding robustness and resource management, and some Javadoc enhancements for the new public API methods.
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
…add-back-tdf-info-methods
| /gemini review | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request reintroduces methods for examining TDF manifests and policies, a capability that was lost in a previous refactoring. The changes are well-structured, and I appreciate the simplification of Manifest.readManifest to accept a String, which cleans up the API. The new functionality is clearly exposed through the SDK class and is supported by a new example and tests.
My review has identified a significant performance issue where the manifest is repeatedly read and parsed. I've also noted a minor issue in a test file concerning character encoding that could impact test portability. The feedback provided aims to address these points to improve the efficiency and robustness of the code.
…add-back-tdf-info-methods
| 
 | 
🤖 I have created a release *beep* *boop* --- <details><summary>0.10.0</summary> ## [0.10.0](v0.9.0...v0.10.0) (2025-09-02) ### ⚠ BREAKING CHANGES * **sdk:** add base key and support for key grants in ZTDF ([#271](#271)) ### Features * ability to set connect-rpc protocol ([#285](#285)) ([47041c5](47041c5)) * add system metadata assertion ([#270](#270)) ([d235f13](d235f13)) * expose AuthorizationService v2 ([#287](#287)) ([d1fd106](d1fd106)) * introduce the base key for nano flows ([#273](#273)) ([d337704](d337704)) * **sdk:** add base key and support for key grants in ZTDF ([#271](#271)) ([c3b79db](c3b79db)) ### Bug Fixes * **ci:** Update codeql.yaml to run on all pull requests ([#283](#283)) ([9e318bb](9e318bb)) * create AES-256 keys of the correct length with all curves ([#282](#282)) ([95c20b3](95c20b3)) * **sdk:** add methods to examine Manifest and Policy ([#278](#278)) ([03d5d41](03d5d41)) * **sdk:** parse the component sizes ([#286](#286)) ([3b1bb69](3b1bb69)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>



These capabilities were removed during a previous refactoring
Also change
Manifest.readManfestto take in aStringsince that's theonly way it's ever used.