3 ms·
This might be pedantic of me, but conflating RLS and auth isn't a great look. RLS is a general purpose mechanism for constraining row operations, and auth has
by pkghost 6y ago
This might be pedantic of me, but conflating RLS and auth isn't
a great look. RLS is a general purpose mechanism for constraining row operations, and auth has to do with usernames and passwords and session tokens.
- pdimitar 6y agoMaybe they mean authorisation rather than authentication but like you, I am curious if they will elaborate further on how is Postgres RLS used.
- lukeramsden 6y agoProbably similar in an overall sense to Postgraphile et al[0], in case you haven't seen that - although I am also interested in the specifics relating to Supabase. [0] https://www.graphile.org/postgraphile/security/ https://www.graphile.org/postgraphile/security/
- lukeramsden 6y agoAs far as pedantry goes, wouldn't conflating RLS and AuthN be wrong, but AuthZ sort-of correct? At least, that's my understanding.
- kiwicopple 6y agoThis is what we are targeting: http://postgrest.org/en/v7.0.0/auth.html http://postgrest.org/en/v7.0.0/auth.html We are still doing a heavy assessment of whether this model can be generalised for everyone. It covers the details of both authentication and authorization - we are just building a nice/easy way to enable this for everyone (probably using the same model as Postgraphile: https://www.graphile.org/postgraphile/security/ https://www.graphile.org/postgraphile/security/)
- mindhash 6y agoi have seen oracle heavily employing RLS for authorization in e-business suite. and it made things so much easier.