17 ms·
This was a shock to us after using RLS for a while. The solution outlined here worked great for us: https://www.benburwell.com/posts/row-level-security-postgres
by markhalonen 4y ago
This was a shock to us after using RLS for a while. The solution outlined here worked great for us: https://www.benburwell.com/posts/row-level-security-postgresql-views/ https://www.benburwell.com/posts/row-level-security-postgres...
- infogulch 4y agoSo they create table-valued functions which support the "SECURITY INVOKER" security context, and then select from that function to form the view. I suppose there's a feature request somewhere to support the "SECURITY INVOKER" feature for views directly?
- infogulch 4y agoWell well lookie here: commitdiff 2022-03-22: Add support for security invoker views. - https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=7faa5fc84bf46ea6c543993cffb8be64dff60d25 https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit... discussion 2021-12-17: [PATCH] Add reloption for views to enable RLS - https://www.postgresql.org/message-id/b66dd6d6-ad3e-c6f2-8b90-47be773da240%40cybertec.at https://www.postgresql.org/message-id/b66dd6d6-ad3e-c6f2-8b9... explanatory blog post: 2022-03-22: Waiting for PostgreSQL 15 – Add support for security invoker views. - https://www.depesz.com/2022/03/22/waiting-for-postgresql-15-add-support-for-security-invoker-views/ https://www.depesz.com/2022/03/22/waiting-for-postgresql-15-... This seems to be slated for PG15: https://www.postgresql.org/docs/15/release-15.html#id-1.11.6.5.5.3.8 https://www.postgresql.org/docs/15/release-15.html#id-1.11.6... > E.1.3.1.6. Privileges: Allow view access to be controlled by privileges of the view user (Christoph Heiss) Previously, view access could only be based on the view owner. Syntatically it will look like: CREATE VIEW vista WITH (security_invoker=true) AS SELECT 'Hello World';