pg.ddx.io  pgsql-docs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
fir for row level security
3+ messages / 2 participants
[nested] [flat]

* fir for row level security
@ 2024-11-01 11:04  PG Doc comments form <noreply@postgresql.org>
  0 siblings, 1 reply; 3+ messages in thread

From: PG Doc comments form @ 2024-11-01 11:04 UTC (permalink / raw)
  To: pgsql-docs@lists.postgresql.org; +Cc: splarv@ya.ru

The following documentation comment has been logged on the website:

Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
Description:

Cite
When multiple policies apply to a given query, they are combined using
either OR (for permissive policies, which are the default) or using AND (for
restrictive policies). This is similar to the rule that a given role has the
privileges of all roles that they are a member of.
end cite

Not clear for what is "this is". May be better "The default behaviour is
similar..."


^ permalink  raw  reply  [nested|flat] 3+ messages in thread

* Re: fir for row level security
@ 2024-11-01 14:23  Bruce Momjian <bruce@momjian.us>
  parent: PG Doc comments form <noreply@postgresql.org>
  0 siblings, 1 reply; 3+ messages in thread

From: Bruce Momjian @ 2024-11-01 14:23 UTC (permalink / raw)
  To: splarv@ya.ru; pgsql-docs@lists.postgresql.org

On Fri, Nov  1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> The following documentation comment has been logged on the website:
> 
> Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> Description:
> 
> Cite
> When multiple policies apply to a given query, they are combined using
> either OR (for permissive policies, which are the default) or using AND (for
> restrictive policies). This is similar to the rule that a given role has the
> privileges of all roles that they are a member of.
> end cite
> 
> Not clear for what is "this is". May be better "The default behaviour is
> similar..."

I see your point.  Attached is a patch which clarifies this.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  When a patient asks the doctor, "Am I going to die?", he means 
  "Am I going to die soon?"

Attachments:

  [text/x-diff] policy.diff (752B, ../../ZyTkXdes2-Gyfyww@momjian.us/2-policy.diff)
  download | inline diff:
diff --git a/doc/src/sgml/ddl.sgml b/doc/src/sgml/ddl.sgml
index f6344b3b79a..b4554253fbe 100644
--- a/doc/src/sgml/ddl.sgml
+++ b/doc/src/sgml/ddl.sgml
@@ -2592,7 +2592,8 @@ GRANT SELECT (col1), UPDATE (col1) ON mytable TO miriam_rw;
    When multiple policies apply to a given query, they are combined using
    either <literal>OR</literal> (for permissive policies, which are the
    default) or using <literal>AND</literal> (for restrictive policies).
-   This is similar to the rule that a given role has the privileges
+   The <literal>OR</literal> behavior is similar to the rule that a given
+   role has the privileges
    of all roles that they are a member of.  Permissive vs. restrictive
    policies are discussed further below.
   </para>

^ permalink  raw  reply  [nested|flat] 3+ messages in thread

* Re: fir for row level security
@ 2024-11-18 20:40  Bruce Momjian <bruce@momjian.us>
  parent: Bruce Momjian <bruce@momjian.us>
  0 siblings, 0 replies; 3+ messages in thread

From: Bruce Momjian @ 2024-11-18 20:40 UTC (permalink / raw)
  To: splarv@ya.ru; pgsql-docs@lists.postgresql.org

On Fri, Nov  1, 2024 at 10:23:25AM -0400, Bruce Momjian wrote:
> On Fri, Nov  1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> > The following documentation comment has been logged on the website:
> > 
> > Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> > Description:
> > 
> > Cite
> > When multiple policies apply to a given query, they are combined using
> > either OR (for permissive policies, which are the default) or using AND (for
> > restrictive policies). This is similar to the rule that a given role has the
> > privileges of all roles that they are a member of.
> > end cite
> > 
> > Not clear for what is "this is". May be better "The default behaviour is
> > similar..."
> 
> I see your point.  Attached is a patch which clarifies this.

Patch applied to master, thanks.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  When a patient asks the doctor, "Am I going to die?", he means 
  "Am I going to die soon?"





^ permalink  raw  reply  [nested|flat] 3+ messages in thread


end of thread, other threads:[~2024-11-18 20:40 UTC | newest]

Thread overview: 3+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-11-01 11:04 fir for row level security PG Doc comments form <noreply@postgresql.org>
2024-11-01 14:23 ` Bruce Momjian <bruce@momjian.us>
2024-11-18 20:40   ` Bruce Momjian <bruce@momjian.us>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox