You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 992a592
Browse filesBrowse the repository at this point in the historyBrowse files
fix(service-analytics): the field reader is always the security service's; changeset (#20917)
The plugin no longer offers its own option for the field-level reader: it
always bridges AnalyticsServiceConfig.getReadableFields to the security
service, and a host composing its own reader constructs AnalyticsService with
it. The changeset records the narrowing, the new optional service hook, and
the ADR-0087 disposition.
Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H
Co-authored-by: Claude <noreply@anthropic.com>
fix(service-analytics)!: every analytics face answers the engine's field-level read refusal, whichever strategy serves the cube: a field the caller may not read is judged before either strategy runs (#20917)
6
+
7
+
Clause-②: yes (narrowing)
8
+
9
+
<!-- adr-0087: not-required (no-migration-prescription) No authorable key, export or stored shape is removed or renamed. The change refuses analytics queries that read a field the caller's field-level permissions hide, which the engine already refuses on the data API and on the ObjectQL strategy, so there is nothing for `objectstack migrate meta` to rewrite. The one public-surface addition is a new optional service hook. -->
10
+
11
+
**BREAKING for analytics queries on a SQL deployment that read a field the caller may not read.**
0 commit comments