Skip to content

Allow list paths

An allow entry is a dot-separated path into the schema, without array indexes. An entry allows the field it names and everything inside it. mongoose-guard resolves every entry against the schema when the guard is created, and throws a GuardConfigError for any entry that doesn’t resolve.

entry = segment *( "." segment )
segment = a schema field name (non-empty)
  • Segments are field names exactly as written in the schema. They’re case-sensitive.
  • Array indexes, wildcards, leading or trailing dots and empty segments are invalid.

Each segment is looked up in turn:

Current segment isNext segment may be
a plain nested objectone of its fields
a sub-schemaone of the sub-schema’s fields
a document arrayone of the element schema’s fields
anything else (String, Number, array of primitives, Map, Mixed, …)nothing. The entry must end here.

A body path matches an entry when, ignoring array indexes, the entry is the path itself or one of its ancestors.

EntryBody pathAllowed?
addressaddress.cityyes, address is an ancestor
address.cityaddress.cityyes
address.cityaddress.zipno
address.cityaddressthe object itself is let through so city can be checked
addresses.cityaddresses.3.cityyes, the index is ignored
profile.links.githubprofile.links.siteno
namenamno, matching is exact per segment

Every message starts with mongoose-guard:.

EntryError
"adress"allow entry "adress" does not match the schema ("adress" not found)
"profile.age"allow entry "profile.age" does not match the schema ("profile.age" not found)
"tags.0"allow entry "tags.0" reaches inside "tags", which has no named fields
"preferences.theme" (Mixed)allow entry "preferences.theme" reaches inside "preferences", which has no named fields
""invalid allow entry ""
"address..city"invalid allow entry "address..city"
allow: "name" (not an array)`allow` must be an array of field paths
PathNotes
_idRejected unless allowed. Rarely a good idea to allow on create routes.
__vMongoose’s version key. Rejected unless allowed.
createdAt, updatedAtAdded by timestamps: true. Rejected unless allowed.
virtualsNot schema paths, so sending one is an unknown_field.