CodamAIDocs
Topicdone

Filters that always run along

What the server invisibly adds to every search: owner, attribute filters, custom mandatory filters, and that the tenant takes effect through the choice of database. Explains why two persons see different matches.

Variants
owner filterattribute filtercustom mandatory filtertenant via databaseattribute missing → 422mandatory filter not applicable → 500

What this is about

Two persons send the same search and get different matches. This is not a bug: CDMS adds filters to every search that the client does not see and cannot switch off.

flowchart TB
    W["AND – root from CDMS"] --> C["your query"]
    W --> O["own data<br/>_userId = logged-in person"]
    W --> A["attribute filter<br/>e.g. companyId IN (companies from the profile)"]
    W --> P["custom mandatory filters<br/>of the project"]
    DB[("Database of the tenant")] -.->|"with MULTI: the tenant takes effect through the choice of database"| W
FilterWhen it runs alongEffect
Own data (owner filter)for models whose objects belong to a persononly objects whose _userId is the logged-in person
Attribute filterwhen the model has an attribute filteronly objects whose field matches an attribute in the profile
Custom mandatory filterswhen the project registers a filter for the modelwhatever the project’s filter specifies
Tenantwhen every tenant has its own database (operating mode MULTI)no filter in the query: CDMS reads directly from the tenant’s database, see SINGLE and MULTI

Details: Only your own data (owner filter), Attribute filter, Custom data filters.

The attribute filter in detail

An attribute filter connects an attribute in the profile of the person with a field in the model. Example: the profile has company: ["123456", "654321"], the model order has the field companyId.

What the attribute filter makes of the profile
Attribute company in the profileFilter on companyId
"123456"companyId = 123456
"123456", "654321" or "123456,654321"companyId IN (123456, 654321)
contains "*"no filter, all orders
missing422 missing-attribute-on-profile|company
present, but empty422 empty-attribute-on-profile|company

A missing or empty attribute never means “see everything”. The request fails instead of returning all data.

The same filters everywhere

The security filters do not only apply to POST /query:

Where the filters run along

When: POST /query

The matches and totalCount contain only what the filters let through.

Result: Two persons, two different lists.

When: POST /read/{id}

An object that the filters exclude does not exist for the person.

Result: 404, see Why invisible objects return 404.

When: expanded list, e.g. { "field": "orders" }

The entries of a list also go through the filters of their model.

Result: Only the visible entries.

When: PUT, PATCH, DELETE

CDMS first checks with the same filters whether the object is visible.

Result: What you are not allowed to read, you cannot change either: 404.

When a mandatory filter is not applicable

No filter is silently dropped: without it the search would return more rows than intended, for a security filter even all of them. A filter from the client that does not fit is therefore rejected (see When a filter does not fit). Security filters are mandatory filters, and with them the error is never the client’s:

Filters from the client and mandatory filters
Filter from the client
  • field unknown or operator does not fit → request rejected
  • 400 unknown-search-key|…, unsupported-operator|…
  • the client corrects its request
Mandatory filter
own data, attribute filter, custom filters
  • field unknown or operator does not fit → search fails
  • 500 unresolvable-mandatory-filter|<feld>|…
  • better no result than too much

Such an error is a configuration error in the project, for example an attribute filter on a field that does not exist in the model.

Traps

Sources in the code and the knowledge base
  • CDMS/cdms-system-layer – AbstractLayer.buildSearchRoot, addSecurityFilters, getCdmsFilter
  • CDMS/cdms-authorization – AbstractAttributeFilter
  • CDMS/cdms-persistence-database – DatabaseConditionBuilder.addWhereFilter (mandatory)
  • CDMS/cdms-integrationtest – AbstractDataFilterTest
Search