Re: RLS open items are vague and unactionable

Поиск
Список
Период
Сортировка
От Robert Haas
Тема Re: RLS open items are vague and unactionable
Дата
Msg-id CA+Tgmob6WzxtfpCT89YxpHzbfM3i4odae+ywjJaunPDd2gu26A@mail.gmail.com
обсуждение исходный текст
Ответ на Re: RLS open items are vague and unactionable  (Stephen Frost <sfrost@snowman.net>)
Список pgsql-hackers
On Fri, Sep 11, 2015 at 9:48 AM, Stephen Frost <sfrost@snowman.net> wrote:
> The only reason to avoid providing that flexibility is the concern that
> it might be misunderstood and users might misconfigure their system.
> Removing the flexibility to have per-command visibility policies and
> instead force a single visibility policy doesn't add any capabilities.

That seems like an extremely weak argument.  If a feature can't be
used for anything useful, the fact that it doesn't actively interfere
with the use of other features that are useful is not a reason to keep
it.  Clearly, something needs to be done about this.  Saying, you can
restrict by something other than ALL but it adds no security and
serves no use cases is, frankly, a ridiculous position.  Tom's
proposal downthread is a reasonable one, and I endorse it: there may
be other approaches as well.  But regardless of the particular
approach, if we're going to have per-command policies, then you need
to do the work to make them useful.

-- 
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: RLS open items are vague and unactionable
Следующее
От: Andres Freund
Дата:
Сообщение: Re: 9.3.9 and pg_multixact corruption