Re: Multi-tenancy with RLS - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Multi-tenancy with RLS
Date
Msg-id 22059.1452876329@sss.pgh.pa.us
Whole thread Raw
In response to Re: Multi-tenancy with RLS  (Stephen Frost <sfrost@snowman.net>)
Responses Re: Multi-tenancy with RLS  (Stephen Frost <sfrost@snowman.net>)
List pgsql-hackers
Stephen Frost <sfrost@snowman.net> writes:
> * Tom Lane (tgl@sss.pgh.pa.us) wrote:
>> Stephen Frost <sfrost@snowman.net> writes:
>>> I don't follow how this would destroy the ability to run pg_dump.
>>> Ideally, we'd have a result where a user could run pg_dump without
>>> having to apply any filters of their own and they'd get a dump of all
>>> objects they're allowed to see.

>> You mean, other than the fact that pg_dump sets row_security = off
>> to ensure that what it's seeing *isn't* filtered.

> There's a specific option to turn it back on already though.

Whereupon you'd have no certainty that what you got represented a
complete dump of your own data.
        regards, tom lane



pgsql-hackers by date:

Previous
From: Benedikt Grundmann
Date:
Subject: Re: Death by regexp_replace
Next
From: Stephen Frost
Date:
Subject: Re: Multi-tenancy with RLS