'op' and 'readSnapshots' middleware only see a projection's target collection. The 'op' context is {collection, id, op}, and ReadSnapshotsRequest has collection, snapshots and snapshotType. So an app can't give a projection different read rules from its target. For example, it can't let anyone read a names projection of users while restricting full users docs: any rule written against users applies to both.
'query' middleware already gets index, which is the projection name. Passing the projection name (or the projection) to the 'op' and 'readSnapshots' contexts too would close the gap. Until then, the access control docs (#737) can only tell people to write read rules against the target collection.
#234 raised the same thing in 2019.
'op'and'readSnapshots'middleware only see a projection's target collection. The'op'context is{collection, id, op}, andReadSnapshotsRequesthascollection,snapshotsandsnapshotType. So an app can't give a projection different read rules from its target. For example, it can't let anyone read anamesprojection ofuserswhile restricting fullusersdocs: any rule written againstusersapplies to both.'query'middleware already getsindex, which is the projection name. Passing the projection name (or the projection) to the'op'and'readSnapshots'contexts too would close the gap. Until then, the access control docs (#737) can only tell people to write read rules against the target collection.#234 raised the same thing in 2019.