Commit 8d2a263
authored
Add accessor field to authorizer rules (#216)
## Description
Adds an optional `accessor` field to authorization rules, exposing
SQLite's 4th authorizer callback argument — the innermost trigger or
view that caused the authorization check.
When querying through a view, SQLite's authorizer fires READ callbacks
with the underlying table name, not the view name. Without the accessor
field, the only way to allow view-based access while blocking direct
table access is to materialize the view into a temporary table.
With the accessor field, rules can scope reads by the view context:
```javascript
{ action: Action.READ, table: "data", accessor: "my_view", policy: Authorization.ALLOW }
```
This allows `SELECT * FROM my_view` (accessor = "my_view") but blocks
`SELECT * FROM data` directly (accessor = null). The `accessor` field
supports exact strings and `{ glob: "pattern" }`, same as other pattern
fields.
The `libsql` Rust crate already exposes this as `AuthContext.accessor:
Option<&str>` — this PR wires it through to the JS rule-matching system.
## How was this change tested?
- [x] Automated test (unit, integration, etc.)
- [ ] Manual test (provide reproducible testing steps below)
Four integration tests added covering view-scoped access, direct access
blocking, glob pattern matching on accessor, and subquery escape
prevention.File tree
4 files changed
+180
-2
lines changed- docs
- integration-tests/tests
- src
4 files changed
+180
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
134 | 134 | | |
135 | 135 | | |
136 | 136 | | |
| 137 | + | |
137 | 138 | | |
138 | 139 | | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
139 | 165 | | |
140 | 166 | | |
141 | | - | |
| 167 | + | |
142 | 168 | | |
143 | 169 | | |
144 | 170 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
464 | 464 | | |
465 | 465 | | |
466 | 466 | | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
467 | 551 | | |
468 | 552 | | |
469 | 553 | | |
| |||
0 commit comments