4 ms·
Security. You have access to stef25_ tables and I don't. The alternative would be we both have access to the same tables with a permission layer to grant acces
by wernercd 3y ago
Security. You have access to stef25_ tables and I don't.
The alternative would be we both have access to the same tables with a permission layer to grant access to row.
Both choices have trade offs but if company makes a mistake and I now have access to your rows? Seems easier to control access at the table layer rather than the column layer.
- stef25 3y agoSurely a where user.id = 123 would fix that ?
- wernercd 3y agoOr user group... or active directory group... or admin group. super user. etc. Or... you can just split things by tables. Or even shard by databases where I don't have access to your database and vice versa. doing stuff in the application and leaving everything in one database/schema is an option... but don't think you aren't making trade offs and leaving open possible issues by not taking the more comprehensive option like sharding. And that's just one question to ask. Another is what about upgrading the database and segregating customers. can't do that if everyone is on the same database/schema. What if a customer doesn't want to be updated or upgraded? Much like companies paying for Windows XP support because stuff they have relies on the older version of software? "where user.id = 123" is a simple solution that quickly becomes more complicate to put it mildly.