From fa6f9f71333e9a7d7733baea37a6311837bad73f Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 1 Oct 2026 00:28:08 +0000 Subject: [PATCH] docs(changeset): correct the scope of two sentences in the pending service-analytics masked-field note The BREAKING banner named only a SQL deployment, while the SQL echo (POST /api/v1/analytics/sql) now refuses the same members whichever strategy serves the cube: its admission runs in callCtx, ahead of the strategy, and the ObjectQL strategy's echo renders without the engine. "What is not affected" read as unconditional, while the plugin bridge's fallback (a security service that predates getQueryableFields, or answers "no answer") refuses every field declaring a maskingRule whoever the caller is, a system context and a capability holder included. The list now carries that condition and points at the New hook paragraph. Claude-Session: https://claude.ai/code/session_01Sfe5YjBLwB9J3y8fvm2xq1 Co-authored-by: Claude --- .../20935-analytics-masked-field-not-queryable.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.changeset/20935-analytics-masked-field-not-queryable.md b/.changeset/20935-analytics-masked-field-not-queryable.md index 6442bc50669..75aa9fa23e8 100644 --- a/.changeset/20935-analytics-masked-field-not-queryable.md +++ b/.changeset/20935-analytics-masked-field-not-queryable.md @@ -8,7 +8,7 @@ Clause-②: yes (narrowing) -**BREAKING for analytics queries on a SQL deployment that group, aggregate, filter or sort by a field the caller may only see masked.** +**BREAKING for analytics queries that group, aggregate, filter or sort by a field the caller may only see masked: on a SQL deployment, and on `POST /api/v1/analytics/sql` whichever strategy serves the cube.** **What changed.** The field-level gate on `POST /api/v1/analytics/query`, `POST /api/v1/analytics/sql` and `POST /api/v1/analytics/dataset/query` judged @@ -20,9 +20,11 @@ member naming a masked field with `403 PERMISSION_DENIED`, in the words the engine uses for the same field. The ObjectQL strategy and the data API already refused these queries. -**What is not affected.** A caller who holds the capability that lifts a -field's masking rule queries the field as before. A system context is -unaffected. A query that names no masked field answers as before. +**What is not affected.** Unless the `security` service predates +`getQueryableFields` or answers "no answer" (see **New hook**): a caller who +holds the capability that lifts a field's masking rule queries the field as +before, a system context is unaffected, and a query that names no masked +field answers as before. **New hook.** `AnalyticsServiceConfig.getQueryableFields(object, context)` supplies the answer. `AnalyticsServicePlugin` wires it to the `security`