Row-level security is only a guarantee if there is no path around it. A rule enforced on the main screen and forgotten on the lookup that fills a dropdown is a leak. This release made a single injector the source of the predicate for every path that reads a secured table.
One rule, many paths
- Declared on the table A rule is a predicate stored with the table's security definition. A placeholder for the table name lets one rule span several tables, for instance a rule that restricts each row to the companies the current user belongs to.
- Foreign-key lookups Hard and soft foreign-key autocompletion were reworked so the executing user is mandatory; the lookup is filtered as the main query is.
- Vertical joins Joined detail data takes the same filter.
- Reports, scripts, cursors The report transformer, scripts and table cursors obtain their resolver from the same injector, so they cannot diverge.
Edges handled
- ANSI joins The injector understands explicit join syntax, not only comma joins.
- Procedures and triggers Injection inside stored-procedure context is isolated so a trigger body is not rewritten as if it were a query.
- Explicit opt-out A select may declare security off, which is visible in review rather than an accident of which path ran.
Two years on, this is the mechanism that lets AI agents and the MCP server query business data at all: the model's SQL goes through the same injector, and the rows it may not see are not fetched.