Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions .changeset/20935-analytics-masked-field-not-queryable.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ Clause-②: yes (narrowing)

<!-- adr-0087: not-required (no-migration-prescription) No authorable key, export or stored shape is removed or renamed. The change refuses analytics queries that group, aggregate, filter or sort by a field the caller may only see masked, which the engine already refuses on the data API and on the ObjectQL strategy, so there is nothing for `objectstack migrate meta` to rewrite. The one public-surface addition is a new optional service hook. -->

**BREAKING for analytics queries on a SQL deployment that group, aggregate, filter or sort by a field the caller may only see masked.**
**BREAKING for analytics queries that group, aggregate, filter or sort by a field the caller may only see masked: on a SQL deployment, and on `POST /api/v1/analytics/sql` whichever strategy serves the cube.**

**What changed.** The field-level gate on `POST /api/v1/analytics/query`,
`POST /api/v1/analytics/sql` and `POST /api/v1/analytics/dataset/query` judged
Expand All @@ -20,9 +20,11 @@ member naming a masked field with `403 PERMISSION_DENIED`, in the words the
engine uses for the same field. The ObjectQL strategy and the data API already
refused these queries.

**What is not affected.** A caller who holds the capability that lifts a
field's masking rule queries the field as before. A system context is
unaffected. A query that names no masked field answers as before.
**What is not affected.** Unless the `security` service predates
`getQueryableFields` or answers "no answer" (see **New hook**): a caller who
holds the capability that lifts a field's masking rule queries the field as
before, a system context is unaffected, and a query that names no masked
field answers as before.

**New hook.** `AnalyticsServiceConfig.getQueryableFields(object, context)`
supplies the answer. `AnalyticsServicePlugin` wires it to the `security`
Expand Down
Loading