5 ms·
If you're using Postgres then using the ltree module is great for permission systems. Available in RDS too
by bencyoung 9mo ago
If you're using Postgres then using the ltree module is great for permission systems. Available in RDS too
- casper14 9mo agoCould you explain why this is great over alternatives?
- nh2 9mo agoDo you have an article about that?
- bencyoung 9mo agoSorry for the delay! It's fairly simple. 1. You have a column on your objects you want secured as an LTREE[] 2. You add a GIST index on that column The values should be the different hierarchy paths to access the object starting with a "type" e.g departments.root.deptA When you run a query, depending on how you want to access you use a <@ query. E.g. I'm a user with root access to all depts "col <@ 'departments.root'::ltree" or I'm a user in dept A "col <@ 'departments.root.deptA'::ltree" etc
- calderwoodra 9mo agoAgreed, specifically for the file structure use-case, we were able to solve this with ltree.
- amcvitty 9mo agoAbout to embark on a similar project. Would love to hear any insights you can share!
- bencyoung 9mo agoSorry for the delay! It's fairly simple. 1. You have a column on your objects you want secured as an LTREE[] 2. You add a GIST index on that column The values should be the different hierarchy paths to access the object starting with a "type" e.g departments.root.deptA When you run a query, depending on how you want to access you use a <@ query. E.g. I'm a user with root access to all depts "col <@ 'departments.root'::ltree" or I'm a user in dept A "col <@ 'departments.root.deptA'::ltree" etc