4 ms·
What guarantees do you offer with query security if I turn this over to an end user? How do I keep them only accessing their own data?
by throwaway115 2y ago
What guarantees do you offer with query security if I turn this over to an end user? How do I keep them only accessing their own data?
- freeone3000 2y agoAny number of database namespacing techniques already present in postgresql can prevent this. Link the user sign-on to a DB user and you’re gold.
- throwaway115 2y agoWhat? How does that ensure user 123 only generates LLM queries that constrain on rows where user=123?
- aazo11 2y agoAs I wrote on the original thread, we recommend using the RDBMS row-level security features. This blog discusses how to do that on Postgres https://www.2ndquadrant.com/en/blog/application-users-vs-row-level-security/ https://www.2ndquadrant.com/en/blog/application-users-vs-row...
- altdataseller 2y agoWay way too complicated. I thought this tool was suppsed to make my life easier
- saigal 2y agois there an easier way?
- altdataseller 2y agoYes write SQL
- saigal 2y agoThe question was around row level security
- deleted 2y ago[deleted]
- aazo11 2y agoWe recommend users leverage row-level security features built into modern RDBMS so the query results only return data for a given user. You can read more on how to do that on Postgres here https://www.2ndquadrant.com/en/blog/application-users-vs-row-level-security/ https://www.2ndquadrant.com/en/blog/application-users-vs-row...
- throwaway115 2y agoWhere do you recommend this? It sounds dangerous for databases that do not implement RLS, like Mysql, MariaDb, Sqlite. I think you should highlight that very clearly somewhere.