Re: row-level security model

Поиск
Список
Период
Сортировка
От Bruno Wolff III
Тема Re: row-level security model
Дата
Msg-id 20040401152656.GA22626@wolff.to
обсуждение исходный текст
Ответ на row-level security model  (John DeSoi <jd@icx.net>)
Ответы Re: row-level security model  (John DeSoi <jd@icx.net>)
Re: row-level security model  (Bricklen <bricklen-rem@yahoo.comz>)
Список pgsql-general
On Wed, Mar 31, 2004 at 12:30:58 -0500,
  John DeSoi <jd@icx.net> wrote:
>
> I want to have multiple groups A, B, C where each group could only see
> a subset of a table (any number of groups would be possible). If a user
> is a member of groups A and B then the rows they can see should be the
> union of what A and B can see. Ideally I could just write a SELECT rule
> for a table or view that would somehow intersect the result rows of the
> query with the result of the security function (I think Oracle has
> something like this). So is it possible to write independent "access"
> functions for each group and have them be dynamically combined based on
> the group membership of the user? I want to do this at the database
> level so the security can be enforced for any application or report
> generator that is allowed to connect.

You should be able to do this with a view. current_user will give you
the user. You probably want to join this with your own group table
and with the table of interest. If each row belongs to only one group
this is easy.

В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Large DB
Следующее
От: weiping he
Дата:
Сообщение: A simple question about Read committed isolation level