pg.ddx.io pgsql-docs@postgresql.org mailing list archive
help / color / mirror / Atom feedfir for row level security
3+ messages / 2 participants
[nested] [flat]
* fir for row level security
@ 2024-11-01 11:04 PG Doc comments form <noreply@postgresql.org>
0 siblings, 1 reply; 3+ messages in thread
From: PG Doc comments form @ 2024-11-01 11:04 UTC (permalink / raw)
To: pgsql-docs@lists.postgresql.org; +Cc: splarv@ya.ru
The following documentation comment has been logged on the website:
Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
Description:
Cite
When multiple policies apply to a given query, they are combined using
either OR (for permissive policies, which are the default) or using AND (for
restrictive policies). This is similar to the rule that a given role has the
privileges of all roles that they are a member of.
end cite
Not clear for what is "this is". May be better "The default behaviour is
similar..."
^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: fir for row level security
@ 2024-11-01 14:23 Bruce Momjian <bruce@momjian.us>
parent: PG Doc comments form <noreply@postgresql.org>
0 siblings, 1 reply; 3+ messages in thread
From: Bruce Momjian @ 2024-11-01 14:23 UTC (permalink / raw)
To: splarv@ya.ru; pgsql-docs@lists.postgresql.org
On Fri, Nov 1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> The following documentation comment has been logged on the website:
>
> Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> Description:
>
> Cite
> When multiple policies apply to a given query, they are combined using
> either OR (for permissive policies, which are the default) or using AND (for
> restrictive policies). This is similar to the rule that a given role has the
> privileges of all roles that they are a member of.
> end cite
>
> Not clear for what is "this is". May be better "The default behaviour is
> similar..."
I see your point. Attached is a patch which clarifies this.
--
Bruce Momjian <bruce@momjian.us> https://momjian.us
EDB https://enterprisedb.com
When a patient asks the doctor, "Am I going to die?", he means
"Am I going to die soon?"
Attachments:
[text/x-diff] policy.diff (752B, ../../ZyTkXdes2-Gyfyww@momjian.us/2-policy.diff)
download | inline diff:
diff --git a/doc/src/sgml/ddl.sgml b/doc/src/sgml/ddl.sgml
index f6344b3b79a..b4554253fbe 100644
--- a/doc/src/sgml/ddl.sgml
+++ b/doc/src/sgml/ddl.sgml
@@ -2592,7 +2592,8 @@ GRANT SELECT (col1), UPDATE (col1) ON mytable TO miriam_rw;
When multiple policies apply to a given query, they are combined using
either <literal>OR</literal> (for permissive policies, which are the
default) or using <literal>AND</literal> (for restrictive policies).
- This is similar to the rule that a given role has the privileges
+ The <literal>OR</literal> behavior is similar to the rule that a given
+ role has the privileges
of all roles that they are a member of. Permissive vs. restrictive
policies are discussed further below.
</para>
^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: fir for row level security
@ 2024-11-18 20:40 Bruce Momjian <bruce@momjian.us>
parent: Bruce Momjian <bruce@momjian.us>
0 siblings, 0 replies; 3+ messages in thread
From: Bruce Momjian @ 2024-11-18 20:40 UTC (permalink / raw)
To: splarv@ya.ru; pgsql-docs@lists.postgresql.org
On Fri, Nov 1, 2024 at 10:23:25AM -0400, Bruce Momjian wrote:
> On Fri, Nov 1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> > The following documentation comment has been logged on the website:
> >
> > Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> > Description:
> >
> > Cite
> > When multiple policies apply to a given query, they are combined using
> > either OR (for permissive policies, which are the default) or using AND (for
> > restrictive policies). This is similar to the rule that a given role has the
> > privileges of all roles that they are a member of.
> > end cite
> >
> > Not clear for what is "this is". May be better "The default behaviour is
> > similar..."
>
> I see your point. Attached is a patch which clarifies this.
Patch applied to master, thanks.
--
Bruce Momjian <bruce@momjian.us> https://momjian.us
EDB https://enterprisedb.com
When a patient asks the doctor, "Am I going to die?", he means
"Am I going to die soon?"
^ permalink raw reply [nested|flat] 3+ messages in thread
end of thread, other threads:[~2024-11-18 20:40 UTC | newest]
Thread overview: 3+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-11-01 11:04 fir for row level security PG Doc comments form <noreply@postgresql.org>
2024-11-01 14:23 ` Bruce Momjian <bruce@momjian.us>
2024-11-18 20:40 ` Bruce Momjian <bruce@momjian.us>
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox