fix(security): skip row security filter for insert queries

Insert queries have no Where clause and read no existing rows, so the
fail-closed check rejected every insert when a row security template
was defined.
This commit is contained in:
Hein
2026-10-01 10:47:54 +02:00
parent daeea241af
commit 1f3bb52a65
+3
View File
@@ -147,6 +147,9 @@ func applyRowSecurity(secCtx SecurityContext, securityList *SecurityList) error
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
case common.DeleteQuery:
secCtx.SetQuery(q.Where(whereClause, whereArgs...))
case common.InsertQuery:
// Inserts read no existing rows, so there is nothing to filter.
logger.Debug("Row security filter not applicable to insert on %s.%s", schema, tablename)
default:
return fmt.Errorf("row security: query type %T on %s.%s does not support Where", secCtx.GetQuery(), schema, tablename)
}