feat(security): exclude hidden/masked columns from create and update payloads

This commit is contained in:
2026-09-30 23:48:09 +02:00
parent a65ca5f5ce
commit b35399fdfa
13 changed files with 456 additions and 4 deletions
+17
View File
@@ -34,6 +34,15 @@ func RegisterSecurityHooks(handler *Handler, securityList *security.SecurityList
return security.PreloadSecurityRules(newSecurityContext(hookCtx), securityList, hookCtx.Operation)
})
// BeforeCreate/BeforeUpdate: drop columns hidden or masked for the user from the
// write payload, so they cannot be inserted or updated.
handler.Hooks().Register(BeforeCreate, func(hookCtx *HookContext) error {
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
})
handler.Hooks().Register(BeforeUpdate, func(hookCtx *HookContext) error {
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
})
// Hook 1: BeforeRead - Load security rules
handler.Hooks().Register(BeforeRead, func(hookCtx *HookContext) error {
secCtx := newSecurityContext(hookCtx)
@@ -133,6 +142,14 @@ func (s *securityContext) SetQuery(query interface{}) {
}
}
func (s *securityContext) GetData() interface{} {
return s.ctx.Data
}
func (s *securityContext) SetData(data interface{}) {
s.ctx.Data = data
}
func (s *securityContext) GetResult() interface{} {
return s.ctx.Result
}