Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.80) (envelope-from ) id 1aEKYZ-0003hb-4N for pgsql-sql@arkaria.postgresql.org; Wed, 30 Dec 2015 17:29:03 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.84) (envelope-from ) id 1aEKYY-0004TQ-Jg for pgsql-sql@arkaria.postgresql.org; Wed, 30 Dec 2015 17:29:02 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84) (envelope-from ) id 1aEKXZ-000245-7C for pgsql-sql@postgresql.org; Wed, 30 Dec 2015 17:28:01 +0000 Received: from out4-smtp.messagingengine.com ([66.111.4.28]) by magus.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.84) (envelope-from ) id 1aEKXR-0000gV-6C for pgsql-sql@postgresql.org; Wed, 30 Dec 2015 17:28:00 +0000 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 2DFA72045A for ; Wed, 30 Dec 2015 12:27:51 -0500 (EST) Received: from frontend2 ([10.202.2.161]) by compute3.internal (MEProxy); Wed, 30 Dec 2015 12:27:51 -0500 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=aklaver.com; h= content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=KzQta+elpA5lGtjOQH/8kMAgFAQ=; b=R1UcvM VV1zJRcFxIC8fXSZ/2LH8fyorvaSihtvLKEA22OnALTTlvjIGWKLrOiymi9HxpE6 KDh92bm8+uts2NUfID2pjyWkHqH5DyflPvqu1J+cg3jRDRRWjuGFtr/EqfV91SYy SEiwoJoQTY8vtq0rk/3HxRq5ofx0ekqWXTdxs= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-sasl-enc:x-sasl-enc; s=smtpout; bh=KzQta+elpA5lGtj OQH/8kMAgFAQ=; b=gsPhOmxs1snAvBHHftmix0aH3Lke5vAfoOuh+tXCos1voCP 9TzKa3uXooA6aYhMNkaNsMOU03Cqkal/NPaO4hpYTz74Q8aeOqidXzSCYwyZ7pvI YzbCifsUV/kltIQ2dRILrWqHZT6EJgmKDrs7LI8ElH1bOTEQ8MQ7XYuh69eE= X-Sasl-enc: wO88jIy5bPrkn+NzOYpBrnUkWDMxtImIjfKv8Tnm2vGl 1451496470 Received: from killi.site (173-160-167-74-washington.hfc.comcastbusiness.net [173.160.167.74]) by mail.messagingengine.com (Postfix) with ESMTPA id 9A23A6801AE; Wed, 30 Dec 2015 12:27:50 -0500 (EST) Subject: Re: question on row level security To: Tim Dudgeon , pgsql-sql@postgresql.org References: <56840D1A.8030203@gmail.com> From: Adrian Klaver Message-ID: <5684143F.1010205@aklaver.com> Date: Wed, 30 Dec 2015 09:28:31 -0800 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.0 MIME-Version: 1.0 In-Reply-To: <56840D1A.8030203@gmail.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-Pg-Spam-Score: -2.7 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-sql Precedence: bulk Sender: pgsql-sql-owner@postgresql.org On 12/30/2015 08:58 AM, Tim Dudgeon wrote: > The new row level security feature in 9.5 looks great. > I guess its designed around the need to restrict access based on the > current database user (current_user) where this maps to a database user. > But most applications now access the database using an application user > and manages data for the applications multiple users (probably with each > user being a row in a USERS table somewhere). > Is there any way to "inject" the application user so that this can be > used in a RLS check? > e.g. conceptually: > > set app_user 'john'; > select * from foo; > > where the select * is restricted by a RLS check that includes 'john' as > the app_user. > Of course custom SQL could be generated for this, but it would be safer > if it could be handled using RLS. > > Any ways to do this? User name maps?: http://www.postgresql.org/docs/9.5/interactive/auth-username-maps.html This still results in an external user becoming a database user. From there you can set up users as members of larger roles, i.e accounting, hr, etc to manage access, or not. > > Tim > > > -- Adrian Klaver adrian.klaver@aklaver.com -- Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-sql