agora inbox for pgsql-docs@postgresql.org
help / color / mirror / Atom feedFrom: Bruce Momjian <bruce@momjian.us>
To: splarv@ya.ru
To: pgsql-docs@lists.postgresql.org
Subject: Re: fir for row level security
Date: Fri, 1 Nov 2024 10:23:25 -0400
Message-ID: <ZyTkXdes2-Gyfyww@momjian.us> (raw)
In-Reply-To: <173045909386.700.9231055113418242392@wrigleys.postgresql.org>
References: <173045909386.700.9231055113418242392@wrigleys.postgresql.org>
On Fri, Nov 1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote:
> The following documentation comment has been logged on the website:
>
> Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html
> Description:
>
> Cite
> When multiple policies apply to a given query, they are combined using
> either OR (for permissive policies, which are the default) or using AND (for
> restrictive policies). This is similar to the rule that a given role has the
> privileges of all roles that they are a member of.
> end cite
>
> Not clear for what is "this is". May be better "The default behaviour is
> similar..."
I see your point. Attached is a patch which clarifies this.
--
Bruce Momjian <bruce@momjian.us> https://momjian.us
EDB https://enterprisedb.com
When a patient asks the doctor, "Am I going to die?", he means
"Am I going to die soon?"
Attachments:
[text/x-diff] policy.diff (752B, ../ZyTkXdes2-Gyfyww@momjian.us/2-policy.diff)
download | inline diff:
diff --git a/doc/src/sgml/ddl.sgml b/doc/src/sgml/ddl.sgml
index f6344b3b79a..b4554253fbe 100644
--- a/doc/src/sgml/ddl.sgml
+++ b/doc/src/sgml/ddl.sgml
@@ -2592,7 +2592,8 @@ GRANT SELECT (col1), UPDATE (col1) ON mytable TO miriam_rw;
When multiple policies apply to a given query, they are combined using
either <literal>OR</literal> (for permissive policies, which are the
default) or using <literal>AND</literal> (for restrictive policies).
- This is similar to the rule that a given role has the privileges
+ The <literal>OR</literal> behavior is similar to the rule that a given
+ role has the privileges
of all roles that they are a member of. Permissive vs. restrictive
policies are discussed further below.
</para>
view thread (3+ messages) latest in thread
Message-ID: <ZyTkXdes2-Gyfyww@momjian.us>
Permalink: ../ZyTkXdes2-Gyfyww@momjian.us/
Also on: postgresql.org/message-id/ZyTkXdes2-Gyfyww@momjian.us
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-docs@postgresql.org
Cc: bruce@momjian.us, splarv@ya.ru, pgsql-docs@lists.postgresql.org
Subject: Re: fir for row level security
In-Reply-To: <ZyTkXdes2-Gyfyww@momjian.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox