Repository navigation
feat(auth): support query-auth BLOB column masking - #1089
Merged
Merged
Conversation
plusplusjiajia
force-pushed
the
query-auth-blob-masking
branch
from
October 10, 2026 04:55
275c8cb to
b0fe76b
Compare
plusplusjiajia
marked this pull request as ready for review
October 10, 2026 05:13
plusplusjiajia
marked this pull request as draft
October 10, 2026 05:14
plusplusjiajia
force-pushed
the
query-auth-blob-masking
branch
from
October 10, 2026 06:22
66de3c1 to
5cee712
Compare
plusplusjiajia
marked this pull request as ready for review
October 10, 2026 07:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Enable BLOB column masking, following the ordinary-column support merged in #1077.
Brief change log
Accept NULL, field-reference and compatible CAST masks on BLOB columns. Masks operate on references; cross-column masks inherit the source's descriptor, view and video-frame settings.
Existing readers resolve payloads when predicates or output need them, preserving OR short-circuiting, null checks and LIMIT. A NULL mask does not open the original payload. BLOB views retain upstream FileIO and REST token handling.
Tests
PK and data-evolution regression tests cover filtering, projection, OR, null checks, batch boundaries and LIMIT. Missing objects verify skipped reads and errors when payloads are required. View and alias tests cover source formats and prevent decoding payloads twice.
Default/fulltext core and REST tests, DataFusion BLOB/query-auth tests, and
cargo fmtpass. All-targets clippy passes in both modes with the existingnonminimal_boolallowance.API and Format
No API or storage format change.
Documentation
Updated the Query Authorization section in
docs/src/sql.md.