Tutorial: Building with CleaveDB
Enforce Security Policies
The ENFORCE SECURITY command defines access rules for documents within a bucket. It evaluates conditions against document fields, session context variables (like my role or @user_id), and graph bond relationships.
Basic policy declaration
Name the policy, bind it to a target bucket, designate the operation scope (read, write, or all), and declare the predicate:
ENFORCE SECURITY "adm" ON docs TO ALLOW all IF my role = "admin"You can also use the keyword form ENFORCE SECURITY POLICY or the alias SHAPE POLICY interchangeably.
Read vs. write policy behavior
CleaveDB handles read and write evaluations with different semantics tailored for security:
- Read Policies: If a read condition fails, the document is silently omitted from
FINDandSCOOPresults—preventing callers from inferring the existence of confidential records. - Write Policies: If a write condition fails on
POURorCHANGE, the operation immediately aborts with an error, preserving database integrity.
Attribute-based comparison
Gate access based on document attributes or user IDs:
ENFORCE SECURITY POLICY "lvl" ON docs TO ALLOW read IF level < 3Or bind writes to document ownership:
ENFORCE SECURITY "own" ON docs TO ALLOW write IF owner = @user_idGraph-Based Access Control (GBAC)
Because CleaveDB is a native graph database, access control can traverse relationships in real time:
ENFORCE SECURITY "owner_only" ON "documents" TO ALLOW read IF bonded as "owner" to my user_idThe engine evaluates whether an active bond exists between the document and the caller's ID before granting read access.
