agora inbox for pgsql-sql@postgresql.org
help / color / mirror / Atom feedRLS for superuser
3+ messages / 3 participants
[nested] [flat]
* RLS for superuser
@ 2016-12-08 07:32 Gaurav Tomar <gauravtomar14@gmail.com>
0 siblings, 2 replies; 3+ messages in thread
From: Gaurav Tomar @ 2016-12-08 07:32 UTC (permalink / raw)
To: pgsql-sql
Hi All,
We are developing an application which will connect to the PostgreSQL 9.5
at backend.
We do not want any DB role/user including superuser to access the table
data from the backend, only if the user is logging in from the application
can see the data.
To achieve this we have created policies and enable RLS on the tables. By
enabling the RLS and creating policies we are able to restrict all the DB
user/role including table owner of the table but not able to restrict
superuser.
Regards,
Gaurav
+91 876 265 4621
^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: RLS for superuser
@ 2016-12-08 07:38 MS (direkt) <martin.stoecker@stb-datenservice.de>
parent: Gaurav Tomar <gauravtomar14@gmail.com>
1 sibling, 0 replies; 3+ messages in thread
From: MS (direkt) @ 2016-12-08 07:38 UTC (permalink / raw)
To: pgsql-sql
Hi Gaurav,
you can't restrict superuser rights via RLS.
IMHO that's obvious because superuser will do administrative task like
dump_all and so on.
Regards Martin
Am 08.12.2016 um 08:32 schrieb Gaurav Tomar:
> Hi All,
>
> We are developing an application which will connect to the PostgreSQL
> 9.5 at backend.
> We do not want any DB role/user including superuser to access the
> table data from the backend, only if the user is logging in from the
> application can see the data.
>
> To achieve this we have created policies and enable RLS on the tables.
> By enabling the RLS and creating policies we are able to restrict all
> the DB user/role including table owner of the table but not able to
> restrict superuser.
>
> Regards,
>
> Gaurav
>
> +91 876 265 4621
>
--
Widdersdorfer Str. 415, 50933 Köln; Tel. +49 / 221 / 9544 010
HRB Köln HRB 75439, Geschäftsführer: S. Böhland, S. Rosenbauer
^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: RLS for superuser
@ 2016-12-08 13:54 Stephen Frost <sfrost@snowman.net>
parent: Gaurav Tomar <gauravtomar14@gmail.com>
1 sibling, 0 replies; 3+ messages in thread
From: Stephen Frost @ 2016-12-08 13:54 UTC (permalink / raw)
To: Gaurav Tomar <gauravtomar14@gmail.com>; +Cc: pgsql-sql
Greetings,
* Gaurav Tomar (gauravtomar14@gmail.com) wrote:
> We are developing an application which will connect to the PostgreSQL 9.5
> at backend.
> We do not want any DB role/user including superuser to access the table
> data from the backend, only if the user is logging in from the application
> can see the data.
Superuser can bypass all security through other means (consider the
pageinspect extension, which allows direct reading of any page in the
database, or the pg_read_file() function which allows reading of whole
files directly, and there are many more ways).
> To achieve this we have created policies and enable RLS on the tables. By
> enabling the RLS and creating policies we are able to restrict all the DB
> user/role including table owner of the table but not able to restrict
> superuser.
The table owner will always be able to disable RLS on the table, or to
drop and recreate the table. I'm not sure how you feel that's
"restricting" the table owner, because it really isn't.
Leveraging SELinux and similar technologies is an approach to being
able to limit what a PG superuser could do, but that doesn't seem like
what you're looking for here.
Thanks!
Stephen
Attachments:
[application/pgp-signature] signature.asc (818B, ../../20161208135359.GB23417@tamriel.snowman.net/2-signature.asc)
download
^ permalink raw reply [nested|flat] 3+ messages in thread
end of thread, other threads:[~2016-12-08 13:54 UTC | newest]
Thread overview: 3+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2016-12-08 07:32 RLS for superuser Gaurav Tomar <gauravtomar14@gmail.com>
2016-12-08 07:38 ` MS (direkt) <martin.stoecker@stb-datenservice.de>
2016-12-08 13:54 ` Stephen Frost <sfrost@snowman.net>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox