Summary
Add an opt-in allow-list mode that restricts filtering and sorting to an explicit set of properties. This complements the existing AllowUnknownProperties and PreventFilter/PreventSort deny-list controls with an allow-list alternative.
Motivation
Today, a consumer must remember to call PreventFilter() or PreventSort() on every property they want to hide. Every property is filterable and sortable by default unless explicitly blocked. For applications with sensitive fields, an allow-list (explicit opt-in per property) is safer by default than a deny-list, because a newly added property does not become queryable by accident.
Proposed behavior
- Add a configuration option, for example
config.UseAllowList() or similar, that switches a given entity or the whole configuration to allow-list mode.
- In allow-list mode, a property is filterable or sortable only if it has an explicit
HasQueryName(...) or an equivalent explicit opt-in call.
- A filter or sort referencing a property outside the allow-list throws the same
UnknownFilterPropertyException/SortParsingException that an unrecognized property throws today.
- Allow-list mode is opt-in and off by default, so existing consumers see no behavior change.
Context
This came out of a security review of the filter and sort parsers. The review scoped allow-list mode out of the immediate bug-fix work, and recommended tracking it here as a follow-up feature.
Summary
Add an opt-in allow-list mode that restricts filtering and sorting to an explicit set of properties. This complements the existing
AllowUnknownPropertiesandPreventFilter/PreventSortdeny-list controls with an allow-list alternative.Motivation
Today, a consumer must remember to call
PreventFilter()orPreventSort()on every property they want to hide. Every property is filterable and sortable by default unless explicitly blocked. For applications with sensitive fields, an allow-list (explicit opt-in per property) is safer by default than a deny-list, because a newly added property does not become queryable by accident.Proposed behavior
config.UseAllowList()or similar, that switches a given entity or the whole configuration to allow-list mode.HasQueryName(...)or an equivalent explicit opt-in call.UnknownFilterPropertyException/SortParsingExceptionthat an unrecognized property throws today.Context
This came out of a security review of the filter and sort parsers. The review scoped allow-list mode out of the immediate bug-fix work, and recommended tracking it here as a follow-up feature.