feat(security): exclude hidden/masked columns from create and update payloads

This commit is contained in:
2026-09-30 23:48:09 +02:00
parent a65ca5f5ce
commit b35399fdfa
13 changed files with 456 additions and 4 deletions
+6
View File
@@ -226,6 +226,12 @@ type ColumnSecurityProvider interface {
}
```
Write side (`RegisterSecurityHooks`, all specs except funcspec):
- Columns with a `hide` or `mask` rule (single-element `Path`) are removed from create/update payloads in `BeforeCreate`/`BeforeUpdate`; the write is not rejected.
- Match is case-insensitive on the rule path vs payload key, model field/JSON name or `gorm` column.
- Rules are preloaded in `BeforeHandle` (outside the tx); the hook only reads the cache and fails closed if rules were not loaded.
- Not covered: nested child records, nested `Path` (JSON sub-values), funcspec.
#### 3. RowSecurityProvider
Manages row-level security (WHERE clause filtering):