Skip to main content

queryModelWithPermissions

@webda/core


Function: queryModelWithPermissions()

queryModelWithPermissions<T>(model, query, context): Promise<{ continuationToken?: string; results: T[]; }>

Defined in: packages/core/src/models/permissions.ts:532

Query a model as the caller

  • the client query may not read private (__) fields (400), and its LIMIT is lowered to MAX_QUERY_LIMIT;
  • a model defining neither canAct form refuses every row: the store is not asked;
  • the model's static getPermissionQuery(context) is ANDed into the query;
  • every result is checked with the static canAct(context, "get", row) and refused ones are dropped. Refused rows are replaced by continuing the scan (next store pages, asking only for the missing rows), within a budget of SCAN_FACTOR x LIMIT rows (between MIN_SCANNED_ROWS and MAX_SCANNED_ROWS) and MAX_REFILL_PAGES store pages. When the budget is spent, an empty page carries no token;
  • the continuation token is sealed (sealContinuationToken): a store token counting or naming rows (Postgres/Firestore offsets, Dynamo keys, memory offsets) would otherwise reveal hidden matches. It is bound to the model, the query and the caller, expires after CONTINUATION_TOKEN_TTL_MS, and is sent back as is in OFFSET; any other value is a 400.

Type Parameters​

T​

T = any

Parameters​

model​

any

the model class

query​

string

the client query

context​

IOperationContext

the caller context

Returns​

Promise<{ continuationToken?: string; results: T[]; }>

the query results the caller may read