agora inbox for pgsql-sql@postgresql.org  
help / color / mirror / Atom feed
From: Karsten Hilbert <Karsten.Hilbert@gmx.net>
To: pgsql-sql@postgresql.org
Subject: Re: question on row level security
Date: Wed, 30 Dec 2015 18:37:15 +0100
Message-ID: <20151230173715.GA27891@hermes.hilbert.loc> (raw)
In-Reply-To: <5684142D.9070701@gmail.com>
References: <56840D1A.8030203@gmail.com>
	<CAKFQuwaqtnVAQaVK1btsftjft39QpsF0oY=QoAFGSJFo2ozRaQ@mail.gmail.com>
	<5684142D.9070701@gmail.com>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>

On Wed, Dec 30, 2015 at 05:28:13PM +0000, Tim Dudgeon wrote:

> >    The new row level security feature in 9.5 looks great.
> >    I guess its designed around the need to restrict access based on
> >    the current database user (current_user) where this maps to a
> >    database user.
> >    But most applications now access the database using an application
> >    user and manages data for the applications multiple users
> >    (probably with each user being a row in a USERS table somewhere).
> >    Is there any way to "inject" the application user so that this can
> >    be used in a RLS check?
> >    e.g. conceptually:
> >
> >    set app_user 'john';
> >    select * from foo;
> >
> >    where the select * is restricted by a RLS check that includes
> >    'john' as the app_user.
> >    Of course custom SQL could be generated for this, but it would be
> >    safer if it could be handled using RLS.
> >
> >    Any ways to do this

You could store a session cookie (say, the app_user) into a
table and have the RLS policy refer to that, no ?

Karsten
-- 
GPG key ID E4071346 @ eu.pool.sks-keyservers.net
E167 67FD A291 2BEA 73BD  4537 78B9 A9F9 E407 1346


-- 
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql



view thread (8+ messages)  latest in thread

Message-ID: <20151230173715.GA27891@hermes.hilbert.loc>
Permalink:  ../20151230173715.GA27891@hermes.hilbert.loc/
Also on:    postgresql.org/message-id/20151230173715.GA27891@hermes.hilbert.loc

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-sql@postgresql.org
  Cc: Karsten.Hilbert@gmx.net
  Subject: Re: question on row level security
  In-Reply-To: <20151230173715.GA27891@hermes.hilbert.loc>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox