mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-05 21:06:28 +00:00
fix(security): apply row security to update and delete queries
ApplyRowSecurity only accepted common.SelectQuery, so the BeforeScan hook failed closed on update/delete when a row-security template existed. Type-switch on SelectQuery, UpdateQuery and DeleteQuery; other types still return an error.
This commit is contained in:
@@ -140,11 +140,16 @@ func applyRowSecurity(secCtx SecurityContext, securityList *SecurityList) error
|
||||
|
||||
// A filter that cannot be attached must fail the request; silently
|
||||
// skipping it would expose every row.
|
||||
selectQuery, ok := secCtx.GetQuery().(common.SelectQuery)
|
||||
if !ok {
|
||||
switch q := secCtx.GetQuery().(type) {
|
||||
case common.SelectQuery:
|
||||
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
|
||||
case common.UpdateQuery:
|
||||
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
|
||||
case common.DeleteQuery:
|
||||
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
|
||||
default:
|
||||
return fmt.Errorf("row security: query type %T on %s.%s does not support Where", secCtx.GetQuery(), schema, tablename)
|
||||
}
|
||||
secCtx.SetQuery(selectQuery.Where(whereClause, whereArgs...))
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
Reference in New Issue
Block a user