Skip to content

Feature request: allow-list mode for filter and sort properties #108

Description

@pdevito3

Summary

Add an opt-in allow-list mode that restricts filtering and sorting to an explicit set of properties. This complements the existing AllowUnknownProperties and PreventFilter/PreventSort deny-list controls with an allow-list alternative.

Motivation

Today, a consumer must remember to call PreventFilter() or PreventSort() on every property they want to hide. Every property is filterable and sortable by default unless explicitly blocked. For applications with sensitive fields, an allow-list (explicit opt-in per property) is safer by default than a deny-list, because a newly added property does not become queryable by accident.

Proposed behavior

  • Add a configuration option, for example config.UseAllowList() or similar, that switches a given entity or the whole configuration to allow-list mode.
  • In allow-list mode, a property is filterable or sortable only if it has an explicit HasQueryName(...) or an equivalent explicit opt-in call.
  • A filter or sort referencing a property outside the allow-list throws the same UnknownFilterPropertyException/SortParsingException that an unrecognized property throws today.
  • Allow-list mode is opt-in and off by default, so existing consumers see no behavior change.

Context

This came out of a security review of the filter and sort parsers. The review scoped allow-list mode out of the immediate bug-fix work, and recommended tracking it here as a follow-up feature.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions