Repository navigation
fix(orm): authorize public projections with complete SQL visibility - #102
Merged
Merged
Conversation
added 4 commits
October 1, 2026 07:05
This was referenced Oct 1, 2026
Dastari
changed the base branch from
feat/complete-group-pages-20261001
to
main
October 1, 2026 07:45
1 of 2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Behavior
A globally installed
RowPolicycurrently rejects every typed projection, even for a model explicitly marked unrestricted. Public certificate inventory therefore cannot use its generated DTO without fetching private custody fields.Use the existing current
ReadVisibilitycontract for pool and pinned-transaction projection reads.Unrestrictedpermits matching rows;Completevalidates the entity/backend and applies the parameterized predicate before ordering, limits and generated key lookups. Callback-only/prefilter policies still fail before SELECTs. Entity and selected-field authorization remain required. No full entity fallback, public GraphQL roots, schema changes or cursor changes.Generated projections supply a doc-hidden identity through a provided trait method. Existing handwritten implementations compile unchanged and retain unrestricted reads; complete predicates fail closed without a matching identity. ORM/macros are aligned at 0.35.1. This PR follows #99 for the combined static release checkpoint; neither this behavior nor the private example requires runtime A–D. Existing MSSQL generated-projection limitations remain unchanged.
Executed verification
ae67b01d9222fae5787e02b553e9a24c21e31797with an installed provider returningUnrestricted; the new fixture failed with the legacy projection-denied error.policy_projectionsexample executed successfully; external consumer warnings-denied Clippy passed SQLite/PostgreSQL/MSSQL. No direct async-graphql dependency or public CRUD roots.No live MSSQL projection execution is claimed; generated MSSQL projections are unsupported. The older PostgreSQL projection fixture still uses ambient URL selection and is not part of the new execution evidence. The new fixture owns its infrastructure and fails if unavailable.
Documentation impact
The source-only release workflow now executes the new owned PostgreSQL projection/relationship lanes and both private examples before publication; its human approval guard is unchanged.
Remaining joined/computed reads, MSSQL summaries/pages and private generated GraphQL views stay open in #91. Release publication uses the coordinated subsequent
.3identity;.2remains at its AI-only commit.