Repository navigation
Commit 6d28dfe
committed
fix(plugin-security, objectql): judge every row a predicate update stores against the row-level check
A row-level `check` (declared, or defaulted from `using`) guarantees
that no stored row fails it. A predicate update (`multi: true`, no row
address) was never judged: the write gate skipped it on the assumption
that a `using`-scoped `where` governed it. A policy that declares only
`check` scopes nothing, and a scoped `where` says nothing about the new
row, so the guarantee did not hold on that path for any policy.
The rows such an update changes are the ones the middleware-composed
query selects, which is complete only once every middleware has run. So
the security layer installs its judgement on the existing
`OperationContext.postHookWriteImageCheck` seam, and the engine runs it
on the predicate path once the payload is final. It hands the seam
every matched row merged with that payload, read by the one matched-row
read the path already makes. One failing row refuses the whole update
with the existing PERMISSION_DENIED / 403 refusal. A seam the engine
never runs fails closed, as it does for an insert. A falsy payload id,
which the engine does not treat as a row address, is judged both ways.
The by-id update and the single-row insert are unchanged. The pending
release note that said bulk updates are not checked row by row is
corrected in place.
Claude-Session: https://claude.ai/code/session_01Evb5jFDZGKQE9KG4jbMfMF
Co-authored-by: Claude <noreply@anthropic.com>1 parent 1fb616e commit 6d28dfe
7 files changed
Lines changed: 367 additions & 84 deletions
File tree
- .changeset
- packages
- objectql/src
- plugins/plugin-security/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2224 | 2224 | | |
2225 | 2225 | | |
2226 | 2226 | | |
2227 | | - | |
2228 | | - | |
| 2227 | + | |
| 2228 | + | |
| 2229 | + | |
| 2230 | + | |
| 2231 | + | |
| 2232 | + | |
| 2233 | + | |
| 2234 | + | |
| 2235 | + | |
| 2236 | + | |
2229 | 2237 | | |
2230 | 2238 | | |
2231 | 2239 | | |
| |||
2237 | 2245 | | |
2238 | 2246 | | |
2239 | 2247 | | |
2240 | | - | |
2241 | | - | |
2242 | | - | |
2243 | | - | |
2244 | | - | |
| 2248 | + | |
| 2249 | + | |
| 2250 | + | |
| 2251 | + | |
| 2252 | + | |
| 2253 | + | |
2245 | 2254 | | |
2246 | 2255 | | |
2247 | 2256 | | |
| |||
13222 | 13231 | | |
13223 | 13232 | | |
13224 | 13233 | | |
| 13234 | + | |
| 13235 | + | |
| 13236 | + | |
| 13237 | + | |
| 13238 | + | |
| 13239 | + | |
| 13240 | + | |
| 13241 | + | |
| 13242 | + | |
| 13243 | + | |
| 13244 | + | |
| 13245 | + | |
| 13246 | + | |
| 13247 | + | |
| 13248 | + | |
| 13249 | + | |
| 13250 | + | |
| 13251 | + | |
| 13252 | + | |
| 13253 | + | |
| 13254 | + | |
| 13255 | + | |
| 13256 | + | |
| 13257 | + | |
| 13258 | + | |
| 13259 | + | |
| 13260 | + | |
| 13261 | + | |
| 13262 | + | |
| 13263 | + | |
| 13264 | + | |
| 13265 | + | |
| 13266 | + | |
| 13267 | + | |
| 13268 | + | |
| 13269 | + | |
| 13270 | + | |
| 13271 | + | |
| 13272 | + | |
| 13273 | + | |
| 13274 | + | |
| 13275 | + | |
| 13276 | + | |
| 13277 | + | |
| 13278 | + | |
| 13279 | + | |
| 13280 | + | |
| 13281 | + | |
| 13282 | + | |
| 13283 | + | |
13225 | 13284 | | |
13226 | 13285 | | |
13227 | 13286 | | |
| |||
Lines changed: 21 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
289 | 289 | | |
290 | 290 | | |
291 | 291 | | |
292 | | - | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
293 | 299 | | |
294 | 300 | | |
295 | 301 | | |
296 | 302 | | |
297 | 303 | | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
298 | 309 | | |
299 | 310 | | |
300 | 311 | | |
| |||
379 | 390 | | |
380 | 391 | | |
381 | 392 | | |
382 | | - | |
| 393 | + | |
383 | 394 | | |
384 | 395 | | |
385 | 396 | | |
| |||
594 | 605 | | |
595 | 606 | | |
596 | 607 | | |
597 | | - | |
598 | | - | |
599 | | - | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
600 | 611 | | |
601 | | - | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
602 | 615 | | |
603 | 616 | | |
604 | 617 | | |
| |||
609 | 622 | | |
610 | 623 | | |
611 | 624 | | |
612 | | - | |
| 625 | + | |
613 | 626 | | |
614 | 627 | | |
615 | 628 | | |
| |||
632 | 645 | | |
633 | 646 | | |
634 | 647 | | |
635 | | - | |
| 648 | + | |
636 | 649 | | |
637 | 650 | | |
638 | 651 | | |
| |||
0 commit comments