mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 03:22:09 +00:00
feat(resolvemcp): require authentication on MCP endpoints and enforce model rules on writes
Guard() rejects unauthenticated callers (no guest/optional mode); Setup*/New* helpers take a SecurityList and have explicit *Unauthenticated variants. Model rules now reach the security hooks, create checks CanCreate (security.CheckModelCreateAllowed), create/update validate keys against the model's writable columns, update sets only given keys (NULL allowed), update and delete go through row security via a new BeforeScan hook, and the annotation tool is opt-in (Config.EnableAnnotations) and runs BeforeHandle.
This commit is contained in:
@@ -441,6 +441,19 @@ func resolveModelRules(secCtx SecurityContext) (modelregistry.ModelRules, bool)
|
||||
return rules, true
|
||||
}
|
||||
|
||||
// CheckModelCreateAllowed returns an error if CanCreate is false for the model. Rules are read
|
||||
// from context with a fallback to the model registry; an unregistered model is allowed.
|
||||
func CheckModelCreateAllowed(secCtx SecurityContext) error {
|
||||
rules, ok := resolveModelRules(secCtx)
|
||||
if !ok {
|
||||
return nil // model not registered, allow by default
|
||||
}
|
||||
if !rules.CanCreate {
|
||||
return fmt.Errorf("create not allowed for %s", secCtx.GetEntity())
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// CheckModelUpdateAllowed is the public wrapper for checkModelUpdateAllowed.
|
||||
func CheckModelUpdateAllowed(secCtx SecurityContext) error {
|
||||
return checkModelUpdateAllowed(secCtx)
|
||||
|
||||
Reference in New Issue
Block a user