feat(resolvemcp): require authentication on MCP endpoints and enforce model rules on writes

Guard() rejects unauthenticated callers (no guest/optional mode); Setup*/New* helpers take a
SecurityList and have explicit *Unauthenticated variants. Model rules now reach the security
hooks, create checks CanCreate (security.CheckModelCreateAllowed), create/update validate keys
against the model's writable columns, update sets only given keys (NULL allowed), update and
delete go through row security via a new BeforeScan hook, and the annotation tool is opt-in
(Config.EnableAnnotations) and runs BeforeHandle.
This commit is contained in:
Hein
2026-10-01 13:31:13 +02:00
parent 7662d5055c
commit ad2f54693f
13 changed files with 643 additions and 104 deletions
+5
View File
@@ -21,6 +21,11 @@ const (
BeforeCreate HookType = "before_create"
AfterCreate HookType = "after_create"
// BeforeScan fires on update and delete, with hookCtx.Query set to the select that loads the
// target row. Hooks that narrow the query (row security) run here; a row the query does
// not return is reported as not found and never written.
BeforeScan HookType = "before_scan"
BeforeUpdate HookType = "before_update"
AfterUpdate HookType = "after_update"