doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

doc: field-level policy - #546

Merged
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy
Jan 9, 2026
Merged

doc: field-level policy#546
ymc9 merged 1 commit into
mainfrom
doc/field-level-policy

Conversation

@ymc9

@ymc9ymc9 commented Jan 7, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Documentation
    • Added comprehensive field-level access control policy documentation with usage examples and behavior specifications.
    • Included detailed explanations of read and update operation constraints and behaviors.
    • Updated roadmap to reflect field-level access control as a completed feature.

✏️ Tip: You can customize this high-level summary in your review settings.

@vercel

vercelBot commented Jan 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
zenstack-new-siteReadyReadyPreview, CommentJan 7, 2026 10:13am

@coderabbitai

Copy link
Copy Markdown
Contributor

Walkthrough

This PR documents field-level access control policies in ORM documentation, including usage examples with @allow and @deny decorators, constraints, read/update behavior, and error handling. The roadmap is updated to mark field-level access control as completed.

Changes

Cohort / File(s)Summary
Field-Level Policy Documentation
docs/orm/access-control/field-level.md
Replaces placeholder heading with comprehensive feature documentation including: imports for AvailableSince and PreviewFeature components, usage examples with @allow/@deny decorators on fields, constraints (read/update only, no relation/computed fields), read behavior with SQL-style null representation, caveat on NULL ambiguity, and update behavior with ORMError rejection details. Samples section marked as "Coming soon!".
Roadmap Update
docs/roadmap.md
Marks field-level access control feature as completed by checking the corresponding roadmap entry checkbox.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • doc: update roadmap #496: Updates the roadmap to mark field-level access control policies as completed, directly overlapping with this PR's roadmap changes.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'doc: field-level policy' directly aligns with the main changes, which document field-level access control policies including read/update behavior and constraints.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
docs/orm/access-control/field-level.md (2)

34-34: Fix subject-verb agreement in sentence.

Line 34 contains a grammatical error: "fields that violates" should be "fields that violate."

Suggested fix
-When reading a row, fields that violates "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:+When reading a row, fields that violate "read" policies will be nullified in the result. Conceptually, the following form of SQL is generated to guard the fields:

48-48: Improve clarity of phrasing in the caveat explanation.

Line 48 reads awkwardly: "Setting unreadable fields null" lacks a preposition. Consider: "Setting unreadable fields to null."

Suggested fix
-Setting unreadable fields null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?+Setting unreadable fields to null brings a caveat that you cannot tell whether a field is actually `NULL` in the database or just unreadable due to access control. So why don't we instead omit the fields from the result?
📜 Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a2475ef and a7dbe6e.

📒 Files selected for processing (2)
  • docs/orm/access-control/field-level.md
  • docs/roadmap.md
🔇 Additional comments (2)
docs/orm/access-control/field-level.md (1)

5-60: Strong documentation for field-level access control policies.

The documentation provides a clear, well-structured introduction to field-level policies. The code example effectively illustrates the feature, and the sections covering constraints, read behavior, update behavior, and caveats comprehensively explain the key concepts. The SQL conceptual representation helps readers understand the underlying mechanism, and the caveat section addresses an important design decision. The roadmap and Samples placeholders set appropriate expectations for readers.

docs/roadmap.md (1)

16-16: Roadmap status update is accurate.

The status change for "Field-level access control" from uncompleted to completed aligns with the comprehensive documentation added in the corresponding file.

@ymc9
ymc9 merged commit 93d913a into mainJan 9, 2026
4 checks passed
@ymc9
ymc9 deleted the doc/field-level-policy branch January 9, 2026 07:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ymc9