diff --git a/.changeset/20935-analytics-masked-field-not-queryable.md b/.changeset/20935-analytics-masked-field-not-queryable.md index 6442bc50669..75aa9fa23e8 100644 --- a/.changeset/20935-analytics-masked-field-not-queryable.md +++ b/.changeset/20935-analytics-masked-field-not-queryable.md @@ -8,7 +8,7 @@ Clause-②: yes (narrowing) -**BREAKING for analytics queries on a SQL deployment that group, aggregate, filter or sort by a field the caller may only see masked.** +**BREAKING for analytics queries that group, aggregate, filter or sort by a field the caller may only see masked: on a SQL deployment, and on `POST /api/v1/analytics/sql` whichever strategy serves the cube.** **What changed.** The field-level gate on `POST /api/v1/analytics/query`, `POST /api/v1/analytics/sql` and `POST /api/v1/analytics/dataset/query` judged @@ -20,9 +20,11 @@ member naming a masked field with `403 PERMISSION_DENIED`, in the words the engine uses for the same field. The ObjectQL strategy and the data API already refused these queries. -**What is not affected.** A caller who holds the capability that lifts a -field's masking rule queries the field as before. A system context is -unaffected. A query that names no masked field answers as before. +**What is not affected.** Unless the `security` service predates +`getQueryableFields` or answers "no answer" (see **New hook**): a caller who +holds the capability that lifts a field's masking rule queries the field as +before, a system context is unaffected, and a query that names no masked +field answers as before. **New hook.** `AnalyticsServiceConfig.getQueryableFields(object, context)` supplies the answer. `AnalyticsServicePlugin` wires it to the `security`