agora inbox for pgsql-sql@postgresql.org  
help / color / mirror / Atom feed
From: Stephen Frost <sfrost@snowman.net>
To: Gaurav Tomar <gauravtomar14@gmail.com>
Cc: pgsql-sql@postgresql.org
Subject: Re: RLS for superuser
Date: Thu, 8 Dec 2016 08:54:00 -0500
Message-ID: <20161208135359.GB23417@tamriel.snowman.net> (raw)
In-Reply-To: <CAByYU3SCUxbA=cepB=L+LYNyQY+bCF+2ONcAjZQBHduiBuk7hA@mail.gmail.com>
References: <CAByYU3SCUxbA=cepB=L+LYNyQY+bCF+2ONcAjZQBHduiBuk7hA@mail.gmail.com>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>

Greetings,

* Gaurav Tomar (gauravtomar14@gmail.com) wrote:
> We are developing an application which will connect to the PostgreSQL 9.5
> at backend.
> We do not want any DB role/user including superuser to access the table
> data from the backend, only if the user is logging in from the application
> can see the data.

Superuser can bypass all security through other means (consider the
pageinspect extension, which allows direct reading of any page in the
database, or the pg_read_file() function which allows reading of whole
files directly, and there are many more ways).

> To achieve this we have created policies and enable RLS on the tables. By
> enabling the RLS and creating policies we are able to restrict all the DB
> user/role including table owner of the table but not able to restrict
> superuser.

The table owner will always be able to disable RLS on the table, or to
drop and recreate the table.  I'm not sure how you feel that's
"restricting" the table owner, because it really isn't.

Leveraging SELinux and similar technologies is an approach to being
able to limit what a PG superuser could do, but that doesn't seem like
what you're looking for here.

Thanks!

Stephen

Attachments:

  [application/pgp-signature] signature.asc (818B, ../20161208135359.GB23417@tamriel.snowman.net/2-signature.asc)
  download

view thread (3+ messages)

Message-ID: <20161208135359.GB23417@tamriel.snowman.net>
Permalink:  ../20161208135359.GB23417@tamriel.snowman.net/
Also on:    postgresql.org/message-id/20161208135359.GB23417@tamriel.snowman.net

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-sql@postgresql.org
  Cc: sfrost@snowman.net, gauravtomar14@gmail.com
  Subject: Re: RLS for superuser
  In-Reply-To: <20161208135359.GB23417@tamriel.snowman.net>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox