feat(security): stamp transaction-local settings on OnTxBegin in all specs

This commit is contained in:
2026-09-30 22:55:26 +02:00
parent 3b93802a25
commit ff76eb8e1f
13 changed files with 386 additions and 2 deletions
+6
View File
@@ -11,6 +11,12 @@ import (
// RegisterSecurityHooks registers all security-related hooks with the handler
func RegisterSecurityHooks(handler *Handler, securityList *security.SecurityList) {
// OnTxBegin: stamp transaction-local settings (e.g. RLS GUCs) before any SQL.
// Looked up per call so SetTxSettings may come after registration.
handler.Hooks().Register(OnTxBegin, func(hookCtx *HookContext) error {
return security.StampTxSettings(newSecurityContext(hookCtx), securityList, hookCtx.Tx)
})
// Hook 0: BeforeHandle - enforce auth after model resolution
handler.Hooks().Register(BeforeHandle, func(hookCtx *HookContext) error {
if err := security.CheckModelAuthAllowed(newSecurityContext(hookCtx), hookCtx.Operation); err != nil {