Received: from magus.postgresql.org (magus.postgresql.org [87.238.57.229]) by mail.postgresql.org (Postfix) with ESMTP id 2BA897E4441 for ; Fri, 22 Jun 2012 09:33:08 -0300 (ADT) Received: from mailout01.ims-firmen.de ([213.174.32.96]) by magus.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1Si32v-0003ha-NY for pgsql-sql@postgresql.org; Fri, 22 Jun 2012 12:33:07 +0000 Received: from mailin02.ims-firmen.de ([192.168.1.142]) by mailout01.ims-firmen.de with esmtp (envelope-from ) id 1Si32i-0006hB-ho for pgsql-sql@postgresql.org; Fri, 22 Jun 2012 14:32:52 +0200 Received: from [87.170.193.77] (helo=a-kretschmer.de) by mailin02.ims-firmen.de with esmtpsa (TLSv1:AES256-SHA:256) (envelope-from ) id 1Si303-0006wJ-5p for pgsql-sql@postgresql.org; Fri, 22 Jun 2012 14:30:07 +0200 Received: from kretschmer by a-kretschmer.de with local (Exim 4.69) (envelope-from ) id 1Si32h-00087O-Go for pgsql-sql@postgresql.org; Fri, 22 Jun 2012 14:32:51 +0200 Date: Fri, 22 Jun 2012 14:32:51 +0200 From: Andreas Kretschmer To: pgsql-sql@postgresql.org Subject: Re: How to limit access only to certain records? Message-ID: <20120622123251.GA30662@tux> References: <4FE458AB.4000109@gmx.net> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <4FE458AB.4000109@gmx.net> X-OS: Debian/GNU Linux - weil ich es mir Wert bin! X-GPG-Fingerprint: EE16 3C01 7B9C 10F7 2C8B 3B86 4DB3 D9EE 7F45 84DA X-Message-Flag: "Windows" is not the answer. "Windows" is the question and the answer is "no"! X-Lugdd: Gerd Kube X-Info: My name is root. Just root. And I am licensed to kill -9 User-Agent: Mutt/1.5.18 (2008-05-17) X-Pg-Spam-Score: -1.9 (-) X-Archive-Number: 201206/72 X-Sequence-Number: 36726 Andreas wrote: > Hi, > > is there a way to limit access for some users only to certain records? > > e.g. there is a customer table and there are account-managers. > Could I limit account-manager #1 so that he only can access customers > only acording to a flag? Yea, it's possible. Write functions to access to the table (for select, for insert and so on) as superuser, with secutity definer, revoke all rights from the user. Users can only access to the table with the functions, within this functions check if the current_user has rights for the record. There are some examples how to do that, please use google ;-) Andreas -- Really, I'm not out to destroy Microsoft. That will just be a completely unintentional side effect. (Linus Torvalds) "If I was god, I would recompile penguin with --enable-fly." (unknown) Kaufbach, Saxony, Germany, Europe. N 51.05082°, E 13.56889°