|
| 1 | +# Write Path Policy |
| 2 | + |
| 3 | +`writePathPolicy` lets a runtime decide whether writes may use both `collection()` and `model()`, or whether a namespace must be written through the Model layer. |
| 4 | + |
| 5 | +The default is intentionally permissive: when `writePathPolicy` is omitted, collection APIs and Model APIs are both allowed. Enable this policy only for applications that want the runtime to enforce a stronger write boundary around schema defaults, hooks, timestamps, optimistic locking, soft delete, and other Model mutation rules. |
| 6 | + |
| 7 | +## Configuration |
| 8 | + |
| 9 | +```ts |
| 10 | +import MonSQLize from 'monsqlize'; |
| 11 | + |
| 12 | +const msq = new MonSQLize({ |
| 13 | + type: 'mongodb', |
| 14 | + databaseName: 'app', |
| 15 | + config: { uri: 'mongodb://localhost:27017' }, |
| 16 | + writePathPolicy: { |
| 17 | + default: 'model-only', |
| 18 | + namespaces: { |
| 19 | + 'app.audit_logs': 'allow-both', |
| 20 | + 'analytics:app.reports': { |
| 21 | + mode: 'allow-both', |
| 22 | + raw: 'block', |
| 23 | + management: 'allow' |
| 24 | + } |
| 25 | + } |
| 26 | + } |
| 27 | +}); |
| 28 | +``` |
| 29 | + |
| 30 | +## Rule Shape |
| 31 | + |
| 32 | +```ts |
| 33 | +type WritePathPolicyMode = 'allow-both' | 'model-only'; |
| 34 | + |
| 35 | +type WritePathPolicyRule = { |
| 36 | + mode?: WritePathPolicyMode; |
| 37 | + raw?: 'inherit' | 'allow' | 'block'; |
| 38 | + management?: 'inherit' | 'allow' | 'block'; |
| 39 | + onViolation?: 'throw' | 'warn'; |
| 40 | +}; |
| 41 | + |
| 42 | +type WritePathPolicyOptions = { |
| 43 | + default?: WritePathPolicyMode | WritePathPolicyRule; |
| 44 | + namespaces?: Record<string, WritePathPolicyMode | WritePathPolicyRule>; |
| 45 | +}; |
| 46 | +``` |
| 47 | + |
| 48 | +| Field | Default | Meaning | |
| 49 | +|-------|---------|---------| |
| 50 | +| `mode` | `allow-both` | `allow-both` allows collection and Model writes. `model-only` blocks direct collection, db, and legacy writes unless overridden. | |
| 51 | +| `raw` | `inherit` | Controls `collection.raw()`, `db.raw()`, and db command access. Inherits `block` from `model-only` and `allow` from `allow-both`. | |
| 52 | +| `management` | `inherit` | Controls index and collection management operations. In `model-only`, Model management methods are allowed while direct collection management is blocked. | |
| 53 | +| `onViolation` | `throw` | `throw` rejects the operation. `warn` logs a warning and allows the operation. | |
| 54 | + |
| 55 | +## Namespace Matching |
| 56 | + |
| 57 | +Namespace rules are matched from most specific to least specific: |
| 58 | + |
| 59 | +1. Internal instance namespace, when present. |
| 60 | +2. Pool-scoped namespace: `poolName:dbName.collectionName`. |
| 61 | +3. Database namespace: `dbName.collectionName`. |
| 62 | +4. Collection name only. |
| 63 | +5. `default`. |
| 64 | + |
| 65 | +Prefer `poolName:dbName.collectionName` or `dbName.collectionName` in user configuration. They are stable across runtime instance IDs. |
| 66 | + |
| 67 | +## Governed Operations |
| 68 | + |
| 69 | +`writePathPolicy` applies to write-capable paths: |
| 70 | + |
| 71 | +- Collection writes: `insertOne`, `insertMany`, `updateOne`, `updateMany`, `replaceOne`, `findOneAndUpdate`, `findOneAndReplace`, `findOneAndDelete`, `upsertOne`, `deleteOne`, `deleteMany`. |
| 72 | +- Batch helpers: `insertBatch`, `updateBatch`, `deleteBatch`, `incrementOne`. |
| 73 | +- Collection management: index creation/drop, collection creation/drop, validators, `renameCollection`, `collMod`, and capped conversion. |
| 74 | +- Raw/db/legacy write surfaces: `collection.raw()`, `db.raw()`, `db.runCommand()`, `dropDatabase()`, and legacy adapter writes. |
| 75 | +- Aggregation pipelines whose final stage writes with `$out` or `$merge`; the policy is checked against the write target namespace. |
| 76 | + |
| 77 | +Read-only queries are not governed by this policy. |
| 78 | + |
| 79 | +## Model-Only Example |
| 80 | + |
| 81 | +```ts |
| 82 | +const msq = new MonSQLize({ |
| 83 | + type: 'mongodb', |
| 84 | + databaseName: 'app', |
| 85 | + config: { uri: 'mongodb://localhost:27017' }, |
| 86 | + writePathPolicy: { default: 'model-only' } |
| 87 | +}); |
| 88 | + |
| 89 | +MonSQLize.Model.define('users', { |
| 90 | + schema: {}, |
| 91 | + options: { |
| 92 | + timestamps: true, |
| 93 | + version: true, |
| 94 | + softDelete: true |
| 95 | + } |
| 96 | +}); |
| 97 | + |
| 98 | +await msq.connect(); |
| 99 | + |
| 100 | +await msq.model('users').insertOne({ name: 'Ada' }); // allowed |
| 101 | +await msq.collection('users').insertOne({ name: 'Ada' }); // throws |
| 102 | +``` |
| 103 | + |
| 104 | +Use namespace overrides for operational collections that intentionally remain native: |
| 105 | + |
| 106 | +```ts |
| 107 | +const msq = new MonSQLize({ |
| 108 | + type: 'mongodb', |
| 109 | + databaseName: 'app', |
| 110 | + config: { uri: 'mongodb://localhost:27017' }, |
| 111 | + writePathPolicy: { |
| 112 | + default: 'model-only', |
| 113 | + namespaces: { |
| 114 | + 'app.audit_logs': 'allow-both' |
| 115 | + } |
| 116 | + } |
| 117 | +}); |
| 118 | +``` |
| 119 | + |
| 120 | +## Boundary |
| 121 | + |
| 122 | +This policy controls the API path used to issue writes. It does not make cache invalidation transaction-atomic, does not make Change Stream sync exactly-once, and does not replace application-level idempotency or authorization. |
0 commit comments