FeatureFuel
1

[Discussion] Column-level permissions: table-level or row-level?

Source: appwrite/appwrite#14153 · opened by @abnegate
Hey everyone 👋 We're adding column-level permissions to Appwrite Databases, and there's one design decision I'd like your input on before we lock anything in: Should column permissions live on the table, or on each row? The answer changes the API, the Console UI, how queries behave and what it costs to run. More detail below. If you only have a minute, skip to [the questions](#questions) at the end. The problem Permissions today decide *whether* you can see a row, never *which parts* of it. If a row has a column some readers shouldn't see (salary, email, phone, internal notes), you currently have to move that column into its own table, give that table its own permissions, and join the two back together in your app. What's the same either way • A permission can optionally name a column. No column means the whole row, so every existing permission keeps meaning exactly what it means today. • It's opt-in per table with a new columnSecurity …

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests