Hasura如何配置select权限过滤拉黑/被拉黑用户的帖子
问题原因
你之前的配置逻辑完全和需求相反:直接嵌套关系条件的默认语义是「该关系存在符合条件的记录」,你用_and连接两个关系条件,等于要求作者必须同时满足「被你拉黑」和「拉黑了你」两个条件,自然只有存在拉黑记录的用户才会命中筛选,没有拉黑记录的普通用户全部被过滤。
正确的Hasura select权限配置
我们的核心逻辑是排除两类用户:你拉黑的用户、拉黑了你的用户,只要任意一类关系存在就排除该作者的帖子,对应权限规则如下:
{ "_and": [ { "deleted_at": { "_is_null": true } }, { "author_profile": { "deleted_at": { "_is_null": true } } }, { "_not": { "author_profile": { "_or": [ // 排除你拉黑的作者:作者作为被拉黑方,拉黑发起者是你 { "been_blocked_by": { "initiator_id": { "_eq": "X-Hasura-User-Id" } } }, // 排除拉黑了你的作者:作者作为拉黑发起方,被拉黑的是你 { "blocked_by_me": { "target_id": { "_eq": "X-Hasura-User-Id" } } } ] } } } ] }
对应原生查询写法
如果不依赖权限规则直接写查询,写法如下:
query GetPosts( $created_at: order_by = desc $limit: Int! = 12 $offset: Int! = 0 $current_user_id: String! = "a" ) { post( limit: $limit offset: $offset order_by: { created_at: $created_at } where: { _and: [ { deleted_at: { _is_null: true } }, { author_profile: { deleted_at: { _is_null: true } } }, { _not: { author_profile: { _or: [ { been_blocked_by: { initiator_id: { _eq: $current_user_id } } }, { blocked_by_me: { target_id: { _eq: $current_user_id } } } ] } } } ] } ) { id author_profile { id first_name } } }
效果验证
用你给出的示例数据,当前用户为a时,返回结果为:
- 作者
a的帖子1(无互拉黑记录) - 作者
c的帖子3(无互拉黑记录) - 作者
d的帖子4(无互拉黑记录)
作者b的帖子2因为被a拉黑被排除,完全符合需求。
内容的提问来源于stack exchange,提问作者Stathis Ntonas
相关产品推荐
相关产品推荐

