Re: Hot to restrict access to subset of data - Mailing list pgsql-general

From Andrus
Subject Re: Hot to restrict access to subset of data
Date
Msg-id da43e5$26sl$1@news.hub.org
Whole thread Raw
In response to Hot to restrict access to subset of data  ("Andrus" <noeetasoftspam@online.ee>)
Responses Re: Hot to restrict access to subset of data
List pgsql-general
"Michael Fuhr" <mike@fuhr.org> wrote in message
news:20050701144604.GA14542@winnie.fuhr.org...
> On Fri, Jul 01, 2005 at 01:56:41PM +0300, Andrus wrote:
>>
>> I want to restrict access to this table based on the user name, document
>> type and access level. I have 3 levels: no access, view only, modify
>> access.
>>
>> Example:
>>
>> User A can only view documents of type X and modify documents of type Y
>> User B can only view documents of type Z
>
> You could use a view: revoke all privileges from the table and grant
> privileges to a view that selects from the table and restricts the
> output based on CURRENT_USER or SESSION_USER (e.g., via a join with
> a permissions table).  For updates you could create a rule on the
> view; see "The Rule System" in the documentation for more information.
>
>> 2. Postgres should allow access from my application only. Is it possible
>> to
>> use authentication method which allows access from my application only ?
>
> You could have the application connect to the database as a particular
> user and grant permissions on the table only to that user.

Thank you. I'm thinking about following approach:

My application connects to Postgres always as superuser, using user name
postgres.
Postgres server as only one user.
Actual users names of users who can access data are stored in special table.
Since only my application knows the super-user password, the users can only
access data
throught my application. My application implements desired level of security
by allowing only pre-defined queries to be run by particular user.

Is this approach secure and better ?

Andrus.



pgsql-general by date:

Previous
From: "Andrus"
Date:
Subject: Which record causes referential integrity violation on delete
Next
From: Gregory Youngblood
Date:
Subject: Re: Hot to restrict access to subset of data