1"use strict";(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[28177],{28453:(e,n,r)=>{r.d(n,{R:()=>i,x:()=>a});var t=r(96540);const s={},o=t.createContext(s);function i(e){const n=t.useContext(o);return t.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:i(e.components),t.createElement(o.Provider,{value:n},e.children)}},75031:(e,n,r)=>{r.r(n),r.d(n,{assets:()=>l,contentTitle:()=>a,default:()=>p,frontMatter:()=>i,metadata:()=>t,toc:()=>d});const t=JSON.parse('{"id":"rules/imports/unresolved-import","title":"unresolved-import","description":"Summary: Unresolved import","source":"@site/projects/regal/rules/imports/unresolved-import.md","sourceDirName":"rules/imports","slug":"/rules/imports/unresolved-import","permalink":"/projects/regal/rules/imports/unresolved-import","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{},"sidebar":"autoSidebar","previous":{"title":"redundant-data-import","permalink":"/projects/regal/rules/imports/redundant-data-import"},"next":{"title":"unresolved-reference","permalink":"/projects/regal/rules/imports/unresolved-reference"}}');var s=r(74848),o=r(28453);const i={},a="unresolved-import",l={},d=[{value:"Rationale",id:"rationale",level:2},{value:"Configuration Options",id:"configuration-options",level:2},{value:"Related Resources",id:"related-resources",level:2}];function c(e){const n={a:"a",code:"code",em:"em",h1:"h1",h2:"h2",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,o.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"unresolved-import",children:"unresolved-import"})}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Summary"}),": Unresolved import"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Category"}),": Imports"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Type"}),": Aggregate - only runs when more than one file is provided for linting"]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.strong,{children:"Avoid"})}),"\n",(0,s.jsx)(n.p,{children:"Imports that can't be resolved."}),"\n",(0,s.jsx)(n.h2,{id:"rationale",children:"Rationale"}),"\n",(0,s.jsxs)(n.p,{children:["OPA does no compile time checks to ensure that references in imports ",(0,s.jsx)(n.em,{children:"resolve"})," to anything, and unresolved references at\nruntime are simply ",(0,s.jsx)(n.strong,{children:"undefined"}),". This is not a bug in OPA, but a necessary feature to allow for dynamic loading of data\nand policy at runtime. The fact that it's not a bug does however not mean that it can't be\n",(0,s.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/491",children:"a problem"}),"! A simple typo, a refactoring, or a mistake, could\neasily lead to an an import being unresolved, and as such undefined at runtime."]}),"\n",(0,s.jsxs)(n.p,{children:["This rule takes a stricter approach to imports, and will have Regal try to resolve them by scanning all the policies it\nis provided for ",(0,s.jsx)(n.strong,{children:"packages"}),", ",(0,s.jsx)(n.strong,{children:"rules"})," and ",(0,s.jsx)(n.strong,{children:"functions"})," that may resolve the import. Note that Regal does not scan any\n",(0,s.jsx)(n.em,{children:"data"})," files. If no reference is found, the rule will flag it as unresolved."]}),"\n",(0,s.jsxs)(n.p,{children:["Since unresolved imports may be perfectly valid \u2014 for example when an import points to data \u2014 this rule provides an\noption in its configuration to except certain paths from being checked. These paths may even contain a wildcard suffix\nto indicate that any path past the wildcard (e.g. ",(0,s.jsx)(n.code,{children:"data.users.*"}),") should be ignored. It is also possible to use a\nregular ",(0,s.jsx)(n.a,{href:"https://www.openpolicyagent.org/projects/regal#inline-ignore-directives",children:"ignore directive"}),":"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-rego",children:"package example\n\n# this is provided as data!\n# regal ignore:unresolved-import\nimport data.users\n"})}),"\n",(0,s.jsx)(n.h2,{id:"configuration-options",children:"Configuration Options"}),"\n",(0,s.jsx)(n.p,{children:"This linter rule provides the following configuration options:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:'rules:\n imports:\n unresolved-import:\n # one of "error", "warning", "ignore"\n level: error\n # list of paths that should be ignored\n # these may be paths to data, or rules that may\n # not be present at the time of linting\
1n except-imports:\n - data.identity.users\n - data.permissions.*\n'})}),"\n",(0,s.jsx)(n.h2,{id:"related-resources",children:"Related Resources"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["OPA Docs: ",(0,s.jsx)(n.a,{href:"https://www.openpolicyagent.org/docs/policy-language/#imports",children:"Imports"})]}),"\n",(0,s.jsxs)(n.li,{children:["OPA Docs: ",(0,s.jsx)(n.a,{href:"https://www.openpolicyagent.org/docs/faq/#collaboration-using-import",children:"Collaboration Using Import"})]}),"\n",(0,s.jsxs)(n.li,{children:["OPA Issues: ",(0,s.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/issues/491",children:"Missing import should create error"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["GitHub: ",(0,s.jsx)(n.a,{href:"https://github.com/open-policy-agent/regal/blob/main/bundle/regal/rules/imports/unresolved-import/unresolved_import.rego",children:"Source Code"})]}),"\n"]}),"\n"]}),"\n"]})]})}function p(e={}){const{wrapper:n}={...(0,o.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.