Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB7o8-0008Sx-M9 for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 18:02:17 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.72) (envelope-from ) id 1UB7o7-0001AD-SI for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 18:02:15 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB7o7-0001A8-2h for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 18:02:15 +0000 Received: from isis.morrow.me.uk ([204.109.63.142]) by magus.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB7o2-0005XR-N5 for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 18:02:14 +0000 Received: from anubis.morrow.me.uk (host86-177-98-144.range86-177.btcentralplus.com [86.177.98.144]) (Authenticated sender: mauzo) by isis.morrow.me.uk (Postfix) with ESMTPSA id 5987A450CE; Thu, 28 Feb 2013 18:02:08 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.7.4 isis.morrow.me.uk 5987A450CE DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=morrow.me.uk; s=dkim201101; t=1362074528; bh=PX7OZXXm1hhXo/xiEK/fRLYvAwfs9QA2PlFu1hCj9o4=; h=Date:From:To:Subject:In-Reply-To; b=NGQ8bs04y9VzKbn9t/sjCdN+FrjQHw5mkIvRn86iR7/3W4F6QFA8OSXv+pRd1iQh+ lMxr9GvfFZzmW6csikICEL1zCJHRW1kud5Czd3PNJCbzTP87kV+ccdD2CGZJ8pFnhy YBwciXxwK9UJiddcc8RgwI6Mhzvvs3YUJcSxZ/fc= X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.97.6 at isis.morrow.me.uk Received: by anubis.morrow.me.uk (Postfix, from userid 5001) id 3FE2399D0; Thu, 28 Feb 2013 18:02:05 +0000 (GMT) Date: Thu, 28 Feb 2013 18:02:05 +0000 From: Ben Morrow To: mark@summersault.com, pgsql-sql@postgresql.org Subject: Re: Need help revoking access WHERE state = 'deleted' Message-ID: <20130228180201.GA10412@anubis.morrow.me.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Newsgroups: pgsql.sql Organization: morrow.me.uk User-Agent: Mutt/1.5.21 (2010-09-15) X-Pg-Spam-Score: -1.2 (-) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-sql Precedence: bulk Sender: pgsql-sql-owner@postgresql.org Quoth mark@summersault.com (Mark Stosberg): > > We are working on a project to start storing some data as "soft deleted" > (WHERE state = 'deleted') instead of hard-deleting it. > > To make sure that we never accidentally expose the deleted rows through > the application, I had the idea to use a view and permissions for this > purpose. > > I thought I could revoke SELECT access to the "entities" table, but then > grant SELECT access to a view: > > CREATE VIEW entities_not_deleted AS SELECT * FROM entities WHERE state > != 'deleted'; > > We could then find/replace in the code to replace references to the > "entities" table with the "entities_not_deleted" table (If you wanted to you could instead rename the table, and use rules on the view to transform DELETE to UPDATE SET state = 'deleted' and copy across INSERT and UPDATE...) > However, this isn't working, I "permission denied" when trying to use > the view. (as the same user that has had their SELECT access removed to > the underlying table.) Works for me. Have you made an explicit GRANT on the view? Make sure you've read section 37.4 'Rules and Privileges' in the documentation, since it explains the ways in which this sort of information hiding is not ironclad. Ben -- Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-sql