dvOutcomeToJson function
An outcome as the server answers, without the columns sensitive names.
The filtering is the point. After lastWriteWins the record this carries
can be another writer's values, so answering with it whole would hand the
device fields it never sent and may not be allowed to read -- a leak with
no error and no log line, through a path the device is entitled to call.
The table knows which columns those are; nothing else on the way out does.
Implementation
Map<String, Object?> dvOutcomeToJson(
DVRemoteOutcome outcome, {
required Set<String> sensitive,
}) {
final DVRecord? record = outcome.record;
return <String, Object?>{
'discarded': outcome.discarded,
if (outcome.rejection != null) 'rejection': outcome.rejection,
if (record != null)
'record': <String, Object?>{
'key': record.key,
'version': record.version,
'values': <String, Object?>{
for (final MapEntry<String, Object?> entry in record.values.entries)
if (!sensitive.contains(entry.key)) entry.key: entry.value,
},
},
};
}