Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cEtIq-0002PO-J1 for pgsql-sql@arkaria.postgresql.org; Thu, 08 Dec 2016 07:39:40 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.84_2) (envelope-from ) id 1cEtIq-0003Om-4L for pgsql-sql@arkaria.postgresql.org; Thu, 08 Dec 2016 07:39:40 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1cEtHs-0002HX-Fi for pgsql-sql@postgresql.org; Thu, 08 Dec 2016 07:38:40 +0000 Received: from mail.inqbus.de ([193.239.28.140]) by magus.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.84_2) (envelope-from ) id 1cEtHp-00050j-Ja for pgsql-sql@postgresql.org; Thu, 08 Dec 2016 07:38:39 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=stb-datenservice.de; s=20160215; h=Content-Type:In-Reply-To:MIME-Version: Date:Message-ID:From:References:To:Subject:Sender:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=EhHaFZMs6XhtLw3zrTTtnr2Q6iYAyHx5ZapVMxgW4WM=; b=GKit0ncNqom79WgpfZgF8i0Bb FPsCTDGG7KdSsQT/U+I5jrI6Sd9UhBq/Lt9D2wJ4uNW3W6U/qf+s9aOoYlcEkywpJH2ETLNW5DY2k tle3tOzeNwTRBY2p5E0eD46Y6oHloPI2nD3XlMo5K9K83bivYP34M6AOMStvjUL2GJGDo=; Received: from ipb218dc62.dynamic.kabel-deutschland.de ([178.24.220.98]:62361 helo=[192.168.178.148]) by mail.inqbus.de with esmtpa (Exim 4.87) (envelope-from ) id 1cEtHo-0002bu-MZ for pgsql-sql@postgresql.org; Thu, 08 Dec 2016 08:38:36 +0100 Subject: Re: RLS for superuser To: pgsql-sql@postgresql.org References: From: "MS (direkt)" Message-ID: <03f83676-a337-ed9b-069a-a36076c0e2d0@stb-datenservice.de> Date: Thu, 8 Dec 2016 08:38:34 +0100 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.5.1 MIME-Version: 1.0 In-Reply-To: Content-Type: multipart/alternative; boundary="------------D5AD7EE71F0E87CD49A95CD7" X-Pg-Spam-Score: -2.0 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-sql Precedence: bulk Sender: pgsql-sql-owner@postgresql.org This is a multi-part message in MIME format. --------------D5AD7EE71F0E87CD49A95CD7 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Hi Gaurav, you can't restrict superuser rights via RLS. IMHO that's obvious because superuser will do administrative task like dump_all and so on. Regards Martin Am 08.12.2016 um 08:32 schrieb Gaurav Tomar: > Hi All, > > We are developing an application which will connect to the PostgreSQL > 9.5 at backend. > We do not want any DB role/user including superuser to access the > table data from the backend, only if the user is logging in from the > application can see the data. > > To achieve this we have created policies and enable RLS on the tables. > By enabling the RLS and creating policies we are able to restrict all > the DB user/role including table owner of the table but not able to > restrict superuser. > > Regards, > > Gaurav > > +91 876 265 4621 > -- Widdersdorfer Str. 415, 50933 Köln; Tel. +49 / 221 / 9544 010 HRB Köln HRB 75439, Geschäftsführer: S. Böhland, S. Rosenbauer --------------D5AD7EE71F0E87CD49A95CD7 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 8bit Hi Gaurav,

you can't restrict superuser rights via RLS.
IMHO that's obvious because superuser will do administrative task like dump_all and so on.

Regards Martin

Am 08.12.2016 um 08:32 schrieb Gaurav Tomar:
Hi All,

We are developing an application which will connect to the PostgreSQL 9.5 at backend.
We do not want any DB role/user including superuser to access the table data from the backend, only if the user is logging in from the application can see the data.

To achieve this we have created policies and enable RLS on the tables. By enabling the RLS and creating policies we are able to restrict all the DB user/role including table owner of the table but not able to restrict superuser. 

Regards,

Gaurav

+91 876 265 4621


-- 
Widdersdorfer Str. 415, 50933 Köln; Tel. +49 / 221 / 9544 010
HRB Köln HRB 75439, Geschäftsführer: S. Böhland, S. Rosenbauer 
--------------D5AD7EE71F0E87CD49A95CD7--