Search Indexing Service  ·  View 20 of 21  ·  Assurance

Identity and Access — One Filtered Query

Fourteen messages, and the filter that is derived rather than supplied.

Editable source SVG draw.io All views
Merchant API Gateway Identity Provider Query Service Definition Registry Recent Writes Alias → idx_v41 1. GET /search?q=… 2. validate token 3. tenant + principal 4. scoped request 5. alias for tenant? 6. alias + relevance v 7. derive ACL filter 8. cost ceiling check 9. query + mandatory filter 10. hits + index version 11. own pending writes? 12. 1 overlay doc 13. results + freshness 14. over ceiling: typed 429 Identity and Access — One Filtered Query The ACL filter is derived at message 7 from the identity, never taken from the request — a caller cannot omit it. v 1.0 · owner Data Platform Architecture

Decisions

  • The ACL filter is derived at the query service from the validated identity and applied before retrieval, so a caller cannot omit it and pagination cannot be poisoned by a post-filter.
  • The alias and the relevance version are resolved from the registry per request, which is how a 60-second relevance rollback reaches live traffic without a deploy.
  • The owner-write overlay is consulted after retrieval and only for the caller's own entities — the one place a stale index is deliberately corrected in the read path.
  • A query over its tenant's cost ceiling gets a typed rejection naming the limit, not a slow answer that degrades a shared cluster.

Risks

  • Registry lookups on every query make the registry a query-path dependency. It is cached with a short TTL, which bounds how fast a rollback can actually propagate.