mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 03:22:09 +00:00
feat(security): exclude hidden/masked columns from create and update payloads
This commit is contained in:
@@ -33,6 +33,15 @@ func RegisterSecurityHooks(handler *Handler, securityList *security.SecurityList
|
||||
return security.PreloadSecurityRules(newSecurityContext(hookCtx), securityList, hookCtx.Operation)
|
||||
})
|
||||
|
||||
// BeforeCreate/BeforeUpdate: drop columns hidden or masked for the user from the
|
||||
// write payload, so they cannot be inserted or updated.
|
||||
handler.Hooks().Register(BeforeCreate, func(hookCtx *HookContext) error {
|
||||
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
|
||||
})
|
||||
handler.Hooks().Register(BeforeUpdate, func(hookCtx *HookContext) error {
|
||||
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
|
||||
})
|
||||
|
||||
// Hook 1: BeforeRead - Load security rules
|
||||
handler.Hooks().Register(BeforeRead, func(hookCtx *HookContext) error {
|
||||
secCtx := newSecurityContext(hookCtx)
|
||||
@@ -120,6 +129,14 @@ func (s *securityContext) SetQuery(query interface{}) {
|
||||
s.ctx.Query = query
|
||||
}
|
||||
|
||||
func (s *securityContext) GetData() interface{} {
|
||||
return s.ctx.Data
|
||||
}
|
||||
|
||||
func (s *securityContext) SetData(data interface{}) {
|
||||
s.ctx.Data = data
|
||||
}
|
||||
|
||||
func (s *securityContext) GetResult() interface{} {
|
||||
return s.ctx.Result
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user