docs: RBAC for text and vector search - #1719
Merged
Merged
Conversation
Add an "Access control" section to the text-search and vector-search pages explaining how fine-grained access control filters results: a node or relationship surfaces only if the caller can read it (labels/type, and both endpoints for relationships) and the matched/indexed property. Notes the per-procedure property gating (search vs search_all/regex), silent dropping, the aggregate limitation, and wildcard-index per-result filtering.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release note
Document how fine-grained access control (RBAC) applies to text search and vector search. Results are now filtered per node/relationship: an entity is returned only if the caller can read it (its labels or edge type, and both endpoints for relationships) and the property the match came from (the queried property for
search, every indexed property forsearch_all/regex_search, the embedding for vector search). Denied hits are silently dropped, andtext_search.aggregatereturns an error under fine-grained restrictions.Related product PRs
PRs from product repo this doc page is related to:
memgraph/memgraph#4316
Checklist:
bugfixorfeaturelabel, based on the product PR type you're documenting