fix(security): apply row security to update and delete queries

ApplyRowSecurity only accepted common.SelectQuery, so the BeforeScan hook
failed closed on update/delete when a row-security template existed.
Type-switch on SelectQuery, UpdateQuery and DeleteQuery; other types
still return an error.
This commit is contained in:
Hein
2026-10-01 09:31:56 +02:00
parent a81031b83d
commit 1e4a76643d
2 changed files with 61 additions and 3 deletions
+8 -3
View File
@@ -140,11 +140,16 @@ func applyRowSecurity(secCtx SecurityContext, securityList *SecurityList) error
// A filter that cannot be attached must fail the request; silently
// skipping it would expose every row.
selectQuery, ok := secCtx.GetQuery().(common.SelectQuery)
if !ok {
switch q := secCtx.GetQuery().(type) {
case common.SelectQuery:
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
case common.UpdateQuery:
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
case common.DeleteQuery:
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
default:
return fmt.Errorf("row security: query type %T on %s.%s does not support Where", secCtx.GetQuery(), schema, tablename)
}
secCtx.SetQuery(selectQuery.Where(whereClause, whereArgs...))
}
return nil