3 ms·
The link Ruslan shared explains how to use row level security with application users as opposed to db users. Basically PostgREST translates cryptographically s
by begriffs 9y ago
The link Ruslan shared explains how to use row level security with application users as opposed to db users.
Basically PostgREST translates cryptographically signed JWT claims from the client request into local SQL variables accessible by postgresql's "current_setting" function. The additional claims can identify the user beyond their db role. They can specify, for instance, the user's email address.
Row level security policies can use current_setting to refer to the extra claims. So multiple users can share a db role and connection pooling works fine.