Re: Database security granularity

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Database security granularity
Дата
Msg-id 26228.1144024044@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Database security granularity  (Michael Trausch <michael.trausch@comcast.nope.net>)
Список pgsql-general
Michael Trausch <michael.trausch@comcast.nope.net> writes:
> I'd like to know if I can constrict database and data access
> on a row-level with PgSQL by using some sort of trickery in the database
> configuration itself.

You could do this with views, on the order of

    create view secure_view as
    select * from base_table where access_allowed(current_user, ...);

where you need to write an access_allowed function that implements your
security policy (probably based on fields in the base table that are not
reflected in the view, so it's not really gonna be "select *").  Then
you grant access to the view but not the base table to the users.

Also, take a look at
    http://pgfoundry.org/projects/veil/
and search the archives for past discussions of row-level security.

            regards, tom lane

В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: 8.1.3, libpq, PQprepare, plpgsql function, and partitioned tables
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: 8.1.3, libpq, PQprepare, plpgsql function, and partitioned tables