Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t6sYl-00GBno-Re for pgsql-docs@arkaria.postgresql.org; Fri, 01 Nov 2024 14:23:31 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1t6sYk-00ELQV-2p for pgsql-docs@arkaria.postgresql.org; Fri, 01 Nov 2024 14:23:30 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t6sYj-00ELQ1-RH for pgsql-docs@lists.postgresql.org; Fri, 01 Nov 2024 14:23:30 +0000 Received: from momjian.us ([72.94.173.45]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t6sYh-003yRh-CF for pgsql-docs@lists.postgresql.org; Fri, 01 Nov 2024 14:23:28 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=momjian.us; s=2024011501; h=In-Reply-To:Content-Type:MIME-Version:References:Message-ID: Subject:To:From:Date:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description; bh=N8E7We6NlBQX0YTLvwF/+pISggc4Kxue1X2JNK2fBCE=; b=hItrV klaY+iqYifgIS9ciPFI7fUUrGs/L8La3D7YKNAowLUQJ2QKZlIEeWzaPmIxdg2kRg6bQhV9u09bF7 DIOp3NyGObmxLTArijU+2pCuAzIVlPYtrlNEVNNCVfatw7jFdgQ0nH3Y2WBt9a+sIFoUMFR/v6RjQ 8aHjZLYLxSLD10Bsv0OdLuu5lQy2TW76gD/eHkcmnKuqtXgO62pS4xE0Na6/37sgriq3jK72QWVDc 8XPHgpzLK60G7qCJDsx/Y5hhIJrVVFeQn1WD1BskQ0FMFTFKKcIyWv6QdPGQBY2zzFykgVkWLTugz H56ihRRVM70ajdlYwCiF0falSL9/w==; Received: from bruce by momjian.us with local (Exim 4.96) (envelope-from ) id 1t6sYf-006sNA-22; Fri, 01 Nov 2024 10:23:25 -0400 Date: Fri, 1 Nov 2024 10:23:25 -0400 From: Bruce Momjian To: splarv@ya.ru, pgsql-docs@lists.postgresql.org Subject: Re: fir for row level security Message-ID: References: <173045909386.700.9231055113418242392@wrigleys.postgresql.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="Y5oCNyhPHQnUGpal" Content-Disposition: inline In-Reply-To: <173045909386.700.9231055113418242392@wrigleys.postgresql.org> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --Y5oCNyhPHQnUGpal Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Fri, Nov 1, 2024 at 11:04:53AM +0000, PG Doc comments form wrote: > The following documentation comment has been logged on the website: > > Page: https://www.postgresql.org/docs/16/ddl-rowsecurity.html > Description: > > Cite > When multiple policies apply to a given query, they are combined using > either OR (for permissive policies, which are the default) or using AND (for > restrictive policies). This is similar to the rule that a given role has the > privileges of all roles that they are a member of. > end cite > > Not clear for what is "this is". May be better "The default behaviour is > similar..." I see your point. Attached is a patch which clarifies this. -- Bruce Momjian https://momjian.us EDB https://enterprisedb.com When a patient asks the doctor, "Am I going to die?", he means "Am I going to die soon?" --Y5oCNyhPHQnUGpal Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="policy.diff" diff --git a/doc/src/sgml/ddl.sgml b/doc/src/sgml/ddl.sgml index f6344b3b79a..b4554253fbe 100644 --- a/doc/src/sgml/ddl.sgml +++ b/doc/src/sgml/ddl.sgml @@ -2592,7 +2592,8 @@ GRANT SELECT (col1), UPDATE (col1) ON mytable TO miriam_rw; When multiple policies apply to a given query, they are combined using either OR (for permissive policies, which are the default) or using AND (for restrictive policies). - This is similar to the rule that a given role has the privileges + The OR behavior is similar to the rule that a given + role has the privileges of all roles that they are a member of. Permissive vs. restrictive policies are discussed further below. --Y5oCNyhPHQnUGpal--