Re: pg_dump & RLS

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: pg_dump & RLS
Дата
Msg-id 2011519.1598036899@sss.pgh.pa.us
обсуждение исходный текст
Ответ на pg_dump & RLS  (Eduard Català <eduard.catala@gmail.com>)
Список pgsql-general
=?UTF-8?Q?Eduard_Catal=C3=A0?= <eduard.catala@gmail.com> writes:
> - ¿is posible to export using pg_dump only the rows that satisfy a rls
> check?
> - Of course, yes, use the --enable-row-security option in pg_dump
> - Yes, but my RLS expression relies on a GUC:
> CREATE POLICY my_policy  ON my_table  USING (company_id =
> *current_setting('company_id')::int*);

That isn't the world's greatest design, but you should be
able to do something like

export PGOPTIONS="-c custom.company_id=42"
pg_dump ...

I kind of wonder why bother with RLS if any user can bypass it
just by changing a GUC, though.  It'd be better for the policy
to check something like role membership.

            regards, tom lane



В списке pgsql-general по дате отправления:

Предыдущее
От: Eduard Català
Дата:
Сообщение: pg_dump & RLS
Следующее
От: Michael Paquier
Дата:
Сообщение: Re: When are largobject records TOASTed into pg_toast_2613?