From ae2b0a4ef43292ee9f669a87d23c37a0e8caa69a Mon Sep 17 00:00:00 2001 From: Hein Date: Thu, 1 Oct 2026 10:47:54 +0200 Subject: [PATCH] fix(security): skip row security filter for insert queries Insert queries have no Where clause and read no existing rows, so the fail-closed check rejected every insert when a row security template was defined. --- pkg/security/hooks.go | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkg/security/hooks.go b/pkg/security/hooks.go index 8b6b300..5bdf0e8 100644 --- a/pkg/security/hooks.go +++ b/pkg/security/hooks.go @@ -147,6 +147,9 @@ func applyRowSecurity(secCtx SecurityContext, securityList *SecurityList) error secCtx.SetQuery(q.Where(whereClause, whereArgs...)) case common.DeleteQuery: secCtx.SetQuery(q.Where(whereClause, whereArgs...)) + case common.InsertQuery: + // Inserts read no existing rows, so there is nothing to filter. + logger.Debug("Row security filter not applicable to insert on %s.%s", schema, tablename) default: return fmt.Errorf("row security: query type %T on %s.%s does not support Where", secCtx.GetQuery(), schema, tablename) }