feat(security): exclude hidden/masked columns from create and update payloads

This commit is contained in:
2026-09-30 23:48:09 +02:00
parent a65ca5f5ce
commit b35399fdfa
13 changed files with 456 additions and 4 deletions
+23
View File
@@ -27,6 +27,21 @@ func RegisterSecurityHooks(handler *Handler, securityList *security.SecurityList
return nil
})
// BeforeHandle: preload column rules for writes before the handler opens its
// transaction; the write hooks below only read the cache.
handler.Hooks().Register(BeforeHandle, func(hookCtx *HookContext) error {
return security.PreloadSecurityRules(newSecurityContext(hookCtx), securityList, hookCtx.Operation)
})
// BeforeCreate/BeforeUpdate: drop columns hidden or masked for the user from the
// write payload, so they cannot be inserted or updated.
handler.Hooks().Register(BeforeCreate, func(hookCtx *HookContext) error {
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
})
handler.Hooks().Register(BeforeUpdate, func(hookCtx *HookContext) error {
return security.ApplyWriteColumnSecurity(newSecurityContext(hookCtx), securityList)
})
// Hook 1: BeforeRead - Load security rules
handler.Hooks().Register(BeforeRead, func(hookCtx *HookContext) error {
secCtx := newSecurityContext(hookCtx)
@@ -122,6 +137,14 @@ func (s *securityContext) SetQuery(query interface{}) {
s.ctx.Metadata["query"] = query
}
func (s *securityContext) GetData() interface{} {
return s.ctx.Data
}
func (s *securityContext) SetData(data interface{}) {
s.ctx.Data = data
}
func (s *securityContext) GetResult() interface{} {
return s.ctx.Result
}