QueryProperties

@ConfigurationProperties(prefix = "wow.query")
class QueryProperties @Autowired(required = false) constructor(var requireExplicitEntry: Boolean = false, var requireAuthenticatedScope: Boolean = false, var http: QueryProperties.Http = Http(), var schema: QueryProperties.Schema = Schema(), var abac: QueryProperties.Abac = Abac(), var sensitivity: QueryProperties.Sensitivity = Sensitivity())

Query settings shared by every entry.

Constructors

Link copied to clipboard
@Autowired(required = false)
constructor(requireExplicitEntry: Boolean = false, requireAuthenticatedScope: Boolean = false, http: QueryProperties.Http = Http(), schema: QueryProperties.Schema = Schema(), abac: QueryProperties.Abac = Abac(), sensitivity: QueryProperties.Sensitivity = Sensitivity())

Types

Link copied to clipboard
data class Abac(@DefaultValue(value = ["false"]) var requirePrincipalTags: Boolean = false, @DefaultValue(value = ["true"]) var matchMissingTagKey: Boolean = true)
Link copied to clipboard
object Companion
Link copied to clipboard
data class Http(@DefaultValue(value = ["1000"]) var maxListSize: Int = 1000, @DefaultValue(value = ["100"]) var maxPageSize: Int = 100, @DefaultValue(value = ["10000"]) var maxPageWindow: Long, @DefaultValue(value = ["128"]) var maxFilterNodes: Int = QueryBudget.DEFAULT_MAX_FILTER_NODES, @DefaultValue(value = ["1000"]) var maxFilterValues: Int = 1000, @DefaultValue(value = ["true"]) var allowExpensiveOperators: Boolean = true, @DefaultValue(value = ["10000"]) var maxResidualGroups: Int = QueryBudget.DEFAULT_MAX_RESIDUAL_GROUPS)

Limits of 0 are disabled.

Link copied to clipboard
data class Schema(@DefaultValue(value = ["5m"]) var revalidateInterval: Duration = java.time.Duration.ofMinutes(5))
Link copied to clipboard
data class Sensitivity(@DefaultValue(value = ["true"]) var displayComparable: Boolean = true)

Properties

Link copied to clipboard

the optional tightenings of AbacQueryPolicy, handed to it as the AbacQueryOptions bean.

Link copied to clipboard

the budget of queries that arrive over HTTP, checked by the gateway at admission.

Link copied to clipboard

rejects (403 IllegalAccessQueryScope) an HTTP query whose authenticated scope does not pin the tenant. The scope an HTTP route resolves from headers or path variables is declared, not authenticated, unless its QueryRequestScope says otherwise. Load, state and tracing routes honour it only under wow.webflux.state.point-read-admission, so turning it on without that fails at startup.

Link copied to clipboard

rejects gateway queries that run without a query entry, so in-process callers must say IN_PROCESS (HTTP routes always say HTTP).

Link copied to clipboard

query schema maintenance.

Link copied to clipboard

how sensitive fields are protected beyond their declared level.