AggregatablePolicy uses ConstantsTrait
What happens to a `?group=` aggregate whose field is **absent** from the model's {@see Arango::AGGREGATABLE} whitelist.
The two halves of a group spec do not answer to the same law by default: by
(the dimensions) is fail-closed through Arango::GROUPABLE, while agg
(the aggregates) has historically let every projected path through. An aggregate
over a field no document carries is not an error in AQL — SUM(null) is 0 —
so the answer comes back well-formed, in 200, and wrong. This policy is how a
consumer closes that door, and picks the noise it wants when it shuts.
new Documents( $container ,
[
Arango::COLLECTION => 'measures' ,
Arango::AGGREGATABLE => [ 'speed' => 'speed.value' , 'weight' ] ,
Arango::AGGREGATABLE_POLICY => AggregatablePolicy::STRICT ,
]) ;
The default is AggregatablePolicy::DROP when a whitelist is declared, and
AggregatablePolicy::OPEN when none is — so a model that never heard of
AGGREGATABLE keeps emitting exactly the query it emitted before.
🚨 Whatever the policy, it gates the whitelist only, never the permission gate:
a whitelisted field refused by Field::REQUIRES is always dropped in silence, even
under AggregatablePolicy::STRICT. An error naming a protected field would
tell the client that field exists — the very oracle the gate is there to close.
Tags
Table of Contents
Constants
- DROP : string = 'drop'
- The aggregate is **dropped** from the response, like an undeclared grouping dimension. The rest of the group survives untouched — dimensions, count, and the group sort (which never references a variable the `COLLECT` did not emit).
- OPEN : string = 'open'
- The aggregate **passes**, on its raw field path. A declared alias still resolves, so the whitelist works as a pure `publicKey => fieldPath` mapping with no gate — the migration ramp for a surface that wants the aliases before it can afford to close the door.
- STRICT : string = 'strict'
- The query **fails** with a `ValidationException` naming the refused token.
Constants
DROP
The aggregate is **dropped** from the response, like an undeclared grouping dimension. The rest of the group survives untouched — dimensions, count, and the group sort (which never references a variable the `COLLECT` did not emit).
public
string
DROP
= 'drop'
The default when a whitelist is declared. Suited to a public API, where a missing column is seen at once.
OPEN
The aggregate **passes**, on its raw field path. A declared alias still resolves, so the whitelist works as a pure `publicKey => fieldPath` mapping with no gate — the migration ramp for a surface that wants the aliases before it can afford to close the door.
public
string
OPEN
= 'open'
The default when no whitelist is declared, and the historical behaviour.
STRICT
The query **fails** with a `ValidationException` naming the refused token.
public
string
STRICT
= 'strict'
Suited to an internal API, where a plain refusal beats a plausible zero.