CodamAIDocs
Topicdone

Attribute filter

An attribute of the person (e.g. projects) restricts a data field. How EQ/IN is formed, what * means, what happens when the attribute is missing and what applies to people with several tenants.

Variants
one value → EQseveral values → IN* → unrestrictedmissing/empty → 422field through a relationseveral attribute filters on one modelPerson with several tenants

What this is about

An attribute filter shows a person only the rows that match a value from their profile. Example: orders order have a field companyId. The profile of a clerk contains the attribute company with the companies she is responsible for. The attribute filter connects the two: she only sees orders of these companies.

An attribute is a named value in a person’s profile, such as company, region or projects. CIAS puts the attributes into the token; CDMS reads them on every request.

From attribute to condition

  1. 1
    CIAS
    puts the person's attributes into the request, e.g. company: ["123456", "654321"]
  2. 2
    CDMS
    reads the attribute company
  3. 3
    CDMS
    splits the values at commas, removes spaces, empty entries and duplicates
  4. 4
    CDMS
    builds the condition for the field companyId
    One value → companyId = 123456. Several values → companyId IN (123456, 654321). The list contains * → no condition at all.
  5. 5
    CDMS→Database
    combines the condition with your request using AND
    Result: Only orders of her own companies come back.

Decision table

Attribute company → condition on companyId
attribute company in the profileResult
"123456"companyId = 123456
"123456", "654321"companyId IN (123456, 654321)
"123456,654321" (one entry with a comma)companyId IN (123456, 654321), as above
contains "*" anywhereno condition, all orders
missing entirely or an empty list422 missing-attribute-on-profile|company
present, but without a usable value, e.g. "" or ","422 empty-attribute-on-profile|company

A single * lifts the filter entirely, even if other values stand next to it.

Where you define an attribute filter

In the hub, on the Filters tab, you connect a profile attribute to a field of the model. The generator creates a filter class from it, e.g. OrderCompanyIdFilter. You do not have to write any code. See Modeling in the hub.

What you can choose as the field

When: The model itself has a field with the value, e.g. companyId.

The condition checks exactly this field.

Result: companyId IN (…)

When: The model points to the object through a relation, e.g. company.

The filter checks the id of the target. The profile then contains the IDs of the companies.

Result: company.id IN (…)

When: Two attribute filters are attached to the model, e.g. company and region.

Both conditions apply at the same time, combined with AND. If one of the attributes is missing, the request fails with 422.

Result: Only rows that match both attributes.

When: The filter is attached to an abstract model.

Every subtype takes it over.

Result: Private and business customers are filtered the same way.

Where the filter applies

The attribute filter runs wherever CDMS reads rows of the model:

RequestEffect
POST /queryOnly matching rows in data; totalCount counts only them.
POST /read/{id}Non-matching row → 404 not-found.
Lists and references in a responseNon-matching entries are missing; a non-matching single reference is null.
PUT, PATCH, DELETE, rollbackCDMS checks with the same filter first: not matching → 404.

See Why invisible objects return 404.

People with several tenants

An attribute can be the same for the person everywhere or have its own value per tenant. If a person works in tenant A, their value for A applies. If they work in tenant B, the value for B applies. A per-tenant value replaces the general value; it is not added to it. If an empty value is stored for the active tenant, the request fails with 422. See One value per person or per tenant.

Pitfalls

Where to go next

Sources in the code and the knowledge base
  • CDMS/cdms-authorization – AbstractAttributeFilter, AttributeValidationException
  • CDMS/cdms-generator – CdmsYamlLoader (accessByAttribute, accessFilters), AttributeFilterProcessor
  • CDMS/cdms-system-layer – AbstractLayer (addSecurityFilters, getCdmsFilter, buildSearchRoot, assertVisibleForWrite)
  • CDMS/cdms-persistence-database – DatabaseConditionBuilder (mandatory filters)
  • CIAS/cias-authentication – TokenParser, EffectiveAttributes
  • CDMS/cdms-authorization – AbstractAttributeFilterTest; CDMS/cdms-integrationtest – AbstractDataFilterTest, OrderFilter, VaultFilter
  • documentation/40-sicherheit/03-attributbasierte-filter.md
Search