Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steve-chavez
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
steve-chavez
3y ago
It wasn't removed, just badly reorganized. It's here now: https://postgrest.org/en/stable/explanations/db_authz.html#s...
62.
▲
by
steve-chavez
3y ago
> I actually discovered this API-schema approach from the docs of one of those tool...I just can't remember which one. Maybe from https://postgrest.org/en/v10.2/schema_structure.html
63.
▲
by
steve-chavez
3y ago
PostgREST docs have always recommended to use only views + functions in a dedicated schema for the API: https://postgrest.org/en/v10.2/schema_structure.html
64.
▲
Finding the right PostgreSQL UUID generation algorithm for FlashMQ.com
(blog.bigsmoke.us)
1 points
by
steve-chavez
3y ago
|
0 comments
65.
▲
Finding the right PostgreSQL UUID generation algorithm for FlashMQ.com
(blog.bigsmoke.us)
2 points
by
steve-chavez
3y ago
|
0 comments
66.
▲
by
steve-chavez
3y ago
I remember feeling like a reached a next level as a software engineer once I started using Vim. It's been almost 10 years now and I still use it (through NeoVim and neovim-qt). Thank you so much Bram!
67.
▲
A REST resource can be the equivalent of a database stored procedure
(postgrest.org)
1 points
by
steve-chavez
3y ago
|
0 comments
68.
▲
by
steve-chavez
3y ago
For that there's security invoker now: CREATE VIEW recent_bookmarks WITH (security_invoker=true) AS SELECT * FROM bookmarks ORDER BY created_at DESC LIMIT 5; Point taken though, it's not the default behavior.
69.
▲
by
steve-chavez
3y ago
Definitely check out "choose your comfort level"[1]. > PostgREST's limitations also had me going back to an API server architecture because I definitely didn't want to write logic in database functions. Because of Pos
70.
▲
by
steve-chavez
3y ago
> because Postgres will check the security for all rows before filtering on the joins, doing anything with WHERE clauses, doing anything to even tentatively take LIMIT into account, etc. Note that the above only happens for non-inlinable
71.
▲
by
steve-chavez
3y ago
Repo at https://github.com/okbob/pspg
72.
▲
Pspg – Postgres Pager[video]
(youtube.com)
2 points
by
steve-chavez
3y ago
|
1 comments
73.
▲
PostgreSQL 16 brings Load Balancing Support in libpq
(mydbops.wordpress.com)
3 points
by
steve-chavez
3y ago
|
0 comments
74.
▲
by
steve-chavez
3y ago
SQL injection is always possible with an ORM, since they always allow executing raw SQL as an escape hatch.
75.
▲
by
steve-chavez
4y ago
Thanks for the honest feedback! There's definitely a lot to improve upon. Not only on features but in documentation as you mention. I'll revisit this issue after launch week.
76.
▲
by
steve-chavez
4y ago
> I keep seeing missing critical features in Postgrest > Example: https://github.com/PostgREST/postgrest/issues/915 > while there isn’t much action on existing issues. That one is planned but it'
77.
▲
by
steve-chavez
4y ago
It's usually exposed to public users. The security model is mostly based on two things: - JWT is used to authenticate API requests. The JWT contains a `role` claim which is a PostgreSQL role that is then used for the duration of the re
78.
▲
Why you should offload your PostgreSQL analytical workloads to ClickHouse
(aiven.io)
5 points
by
steve-chavez
4y ago
|
0 comments
79.
▲
by
steve-chavez
4y ago
https://wiki.postgresql.org/wiki/Inlining_of_SQL_functions
80.
▲
by
steve-chavez
4y ago
> –i-am-a-dummy mode The safeupdate postgres extension[1] does this exactly. safeupdate is a simple extension to PostgreSQL that raises an error if UPDATE and DELETE are executed without specifying conditions [1]: https://gi
81.
▲
by
steve-chavez
4y ago
To be fair, begriffs never shut down any discussion of HATEOAS, previous contributors did - because at the time users were asking for more JSON capabilities from PostgREST and we needed to focus on those. We're still open on adding HAT
82.
▲
by
steve-chavez
4y ago
> It seems like when taken to an extreme, strong HATEOAS would mean you could write a universal client that works across all APIs. And if you go with HAL or JSON-LD, you have to use a specific clients for those formats, so not universal
83.
▲
PostgREST 10 Release Notes
(postgrest.org)
2 points
by
steve-chavez
4y ago
|
0 comments
84.
▲
by
steve-chavez
4y ago
Note that the JS client is deliberately limited in the queries it can perform[1]. You can also be fully restrictive by only allowing the client to call the custom SQL functions[2] you define. In Supabase this is done by having all your tabl
85.
▲
by
steve-chavez
4y ago
How does ReadySet interact with Row level security[1]? For RLS to work you'd need validation at the origin server anyway right? [1]: https://www.postgresql.org/docs/current/ddl-rowsecurity.html
86.
▲
by
steve-chavez
4y ago
That can be solved with RLS. The JWT usually contains the application user id(Customer) and assuming Document has an ownerId column, the SELECT policy for Document would contain the `ownerId = auth.uid()`[1] condition — this would ensure cu
87.
▲
by
steve-chavez
5y ago
What do you think is missing? Do you have any suggestions? In the article HTML is just treated as a `text` type inside the SQL function, you could do the same for rendering different pages - create functions that return HTML as text.
88.
▲
by
steve-chavez
5y ago
Ah, no - PostgREST doesn't have that kind of convention builtin(default to searching an index.html on path). I'll update the gist and change the function to `map.html` to avoid any confusion.
89.
▲
by
steve-chavez
5y ago
Nice! In the past I've also rendered an OSM map[1] with this approach and as you mention caching/CDN should make it suitable for production. [1]: https://gist.github.com/steve-chavez/c1435a8c9583d2524e87e4f...
90.
▲
by
steve-chavez
5y ago
Can second Nix! With Nix we were able to reduce PostgREST image size[1] from over 30 MB to about 4 MB. [1]: https://github.com/PostgREST/postgrest/tree/main/nix/tools/d...
More ›