mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 12:31:59 +00:00
feat(security): stamp transaction-local settings on OnTxBegin in all specs
This commit is contained in:
@@ -11,6 +11,12 @@ import (
|
||||
|
||||
// RegisterSecurityHooks registers all security-related hooks with the handler
|
||||
func RegisterSecurityHooks(handler *Handler, securityList *security.SecurityList) {
|
||||
// OnTxBegin: stamp transaction-local settings (e.g. RLS GUCs) before any SQL.
|
||||
// Looked up per call so SetTxSettings may come after registration.
|
||||
handler.Hooks().Register(OnTxBegin, func(hookCtx *HookContext) error {
|
||||
return security.StampTxSettings(newSecurityContext(hookCtx), securityList, hookCtx.Tx)
|
||||
})
|
||||
|
||||
// Hook 0: BeforeHandle - enforce auth after model resolution
|
||||
handler.Hooks().Register(BeforeHandle, func(hookCtx *HookContext) error {
|
||||
if err := security.CheckModelAuthAllowed(newSecurityContext(hookCtx), hookCtx.Operation); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user