5 ms·
FWIW, you don't need to use database roles if you want to use RLS. You can instead have some other context indicating the current "application user" and use tha
by anarazel 3y ago
FWIW, you don't need to use database roles if you want to use RLS. You can instead have some other context indicating the current "application user" and use that in your RLS policies.
- pphysch 3y agoDo I have to add that context to every query, or is it something I can set per cursor/transaction?
- anarazel 3y agoEither. What the best approach is depends a bit on your needs / security model. You can e.g. something like storing the session "application user" in a configuration variable (SET myapp.rls_user =...). But if the user can influence the SQL and that's part of the threat model, you need to do more, because that could be changed by further SQL. Another solution is to just have a session level temp table indicating the current application user.
- pphysch 3y agoOh sweet. That approach makes a lot more sense. Access would be through a server-side ORM so users would not be able to run arbitrary SQL. Thanks!
- edmundsauto 3y agoSupabase has pretty good docs and a nice Ui to play around with this, btw.