agora inbox for pgsql-docs@postgresql.org  
help / color / mirror / Atom feed
From: Bruce Momjian <bruce@momjian.us>
To: splarv@ya.ru
To: pgsql-docs@lists.postgresql.org
Subject: Re: fir for row level security
Date: Fri, 1 Nov 2024 10:23:25 -0400
Message-ID: <ZyTkXdes2-Gyfyww@momjian.us> (raw)
In-Reply-To: <173045909386.700.9231055113418242392@wrigleys.postgresql.org>
References: <173045909386.700.9231055113418242392@wrigleys.postgresql.org>

On Fri, Nov  1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> The following documentation comment has been logged on the website:
> 
> Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> Description:
> 
> Cite
> When multiple policies apply to a given query, they are combined using
> either OR (for permissive policies, which are the default) or using AND (for
> restrictive policies). This is similar to the rule that a given role has the
> privileges of all roles that they are a member of.
> end cite
> 
> Not clear for what is "this is". May be better "The default behaviour is
> similar..."

I see your point.  Attached is a patch which clarifies this.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  When a patient asks the doctor, "Am I going to die?", he means 
  "Am I going to die soon?"

Attachments:

  [text/x-diff] policy.diff (752B, ../ZyTkXdes2-Gyfyww@momjian.us/2-policy.diff)
  download | inline diff:
diff --git a/doc/src/sgml/ddl.sgml b/doc/src/sgml/ddl.sgml
index f6344b3b79a..b4554253fbe 100644
--- a/doc/src/sgml/ddl.sgml
+++ b/doc/src/sgml/ddl.sgml
@@ -2592,7 +2592,8 @@ GRANT SELECT (col1), UPDATE (col1) ON mytable TO miriam_rw;
    When multiple policies apply to a given query, they are combined using
    either <literal>OR</literal> (for permissive policies, which are the
    default) or using <literal>AND</literal> (for restrictive policies).
-   This is similar to the rule that a given role has the privileges
+   The <literal>OR</literal> behavior is similar to the rule that a given
+   role has the privileges
    of all roles that they are a member of.  Permissive vs. restrictive
    policies are discussed further below.
   </para>

view thread (3+ messages)  latest in thread

Message-ID: <ZyTkXdes2-Gyfyww@momjian.us>
Permalink:  ../ZyTkXdes2-Gyfyww@momjian.us/
Also on:    postgresql.org/message-id/ZyTkXdes2-Gyfyww@momjian.us

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-docs@postgresql.org
  Cc: bruce@momjian.us, splarv@ya.ru, pgsql-docs@lists.postgresql.org
  Subject: Re: fir for row level security
  In-Reply-To: <ZyTkXdes2-Gyfyww@momjian.us>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox