dvOutcomeToJson function

Map<String, Object?> dvOutcomeToJson(
  1. DVRemoteOutcome outcome, {
  2. required Set<String> sensitive,
})

An outcome as the server answers, without the columns sensitive names.

The filtering is the point. After lastWriteWins the record this carries can be another writer's values, so answering with it whole would hand the device fields it never sent and may not be allowed to read -- a leak with no error and no log line, through a path the device is entitled to call. The table knows which columns those are; nothing else on the way out does.

Implementation

Map<String, Object?> dvOutcomeToJson(
  DVRemoteOutcome outcome, {
  required Set<String> sensitive,
}) {
  final DVRecord? record = outcome.record;
  return <String, Object?>{
    'discarded': outcome.discarded,
    if (outcome.rejection != null) 'rejection': outcome.rejection,
    if (record != null)
      'record': <String, Object?>{
        'key': record.key,
        'version': record.version,
        'values': <String, Object?>{
          for (final MapEntry<String, Object?> entry in record.values.entries)
            if (!sensitive.contains(entry.key)) entry.key: entry.value,
        },
      },
  };
}