Repository navigation
Support obfuscated feature flag assignment keys - #3941
leoromanovsky wants to merge 21 commits into
Conversation
|
✅ All CI checks and tests passed. Datadog automation helped this PR pass. 🎉 All green!🧪 All tests passed 🔄 Datadog retried 1 test - 1 passed on retry 🎯 Code Coverage (details) 🔗 Commit SHA: 27ba428 | Docs | View more details | Give us feedback! |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 185a1fa917
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b3779f8916
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 751cb7629d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| sdkCore.getFeature(Feature.FLAGS_FEATURE_NAME) | ||
| ?.withContext(withFeatureContexts = setOf(Feature.RUM_FEATURE_NAME)) { datadogContext -> | ||
| val supportsObfuscation = datadogContext.source == "android" |
There was a problem hiding this comment.
why this is needed? the same SDK working in React Native SDK setup changes behavior?
There was a problem hiding this comment.
JavaScript consumes the snapshot through the bridge. It cannot decode obfuscated keys yet. A native SDK upgrade alone does not make that JavaScript reader compatible.
- How do you think we should handle adding support for this given that the React Native changes have to be layer after this release?
|
Please also follow the convention for the feature PRs: title should contain JIRA ticket reference, branch should be |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71cc4df42d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
@0xnm I don’t see this branch-naming convention documented in AGENTS.md or CONTRIBUTING.md. If it is required, could you please document it there so contributors can follow it from the start? I’ve added the associated Linear ticket to the PR description. I’ll keep the existing branch for this PR rather than disrupt the review already in progress. We can follow the documented convention for future work. |
|
@leoromanovsky Can you update your branch? I pushed some updates to |
Tracking: FFLSDK-261
Motivation
Readable flag keys can reveal upcoming features. Support obfuscated assignments without changing application evaluation calls.
This reduces readable names in payloads; it does not hide values or prevent dictionary guessing. It is not encryption or response signing.
Changes and Decisions
Advertise support through this header instead of a JSON
supported_capabilitiesfield. Existing request fields stay unchanged.X-DD-FEATURE-FLAGS-CAPABILITIES: assignment-encoding-flag-key-256-v1Capabilities are sorted and comma-separated. They describe support, not a requirement. The edge still selects plaintext or obfuscated responses through its rollout.
For
obfuscated: true, validateobfuscation: {scheme, salt}and hash the application key for lookup. The response scheme remainsflag-key-sha256-v1:The public salt contains 16 bytes, encoded as 32 lowercase hexadecimal characters. Keys use exact UTF-8 bytes without normalization.
sequenceDiagram participant App participant SDK as Android Flags client participant Edge as Fastly SDK->>Edge: Precompute request + capability header Edge-->>SDK: Plaintext, or encoded keys + scheme + salt SDK->>SDK: Validate and retain assignments with encoding App->>SDK: Evaluate original flag key SDK->>SDK: Hash lookup key only for encoded assignments SDK-->>App: Original value and evaluation details SDK->>SDK: Keep original flag key in telemetryencodedFlagswith their metadata and context. Continue reading legacy plaintext caches.Release requires edge support for the new header. This PR does not deploy backend changes.
Related: edge rollout, browser implementation.