Live data from Hacker News

Postgres 9.5 Release Notes

postgresql.org

1–10 of 11 posts

Re: Postgres 9.5 Release Notes

#3
Anyone have ever built an application utilising row level security?

In old-school systems you normally have one database user and a connection pool set up in the app with that user. Row level access is handeld with join tables to sort out what data is accessible for the specific users (sent as parameter to most queries).

With row-level security you would crate a db-user for each application user and also its own connection pool?

Re: Postgres 9.5 Release Notes

#6
post #3

Anyone have ever built an application utilising row level security? In old-school systems you normally have one database user and a connection pool set up in the app with that user. Row level access is handeld with join tables to sort out what data is accessible for the specific users (sent as parameter to most queries). With row-level security you would crate a db-user for each application user and also its own conn…

RLS doesn't require the use of a db user. For example you could use a session variable to identify your logical user and use that in the RLS query.

Re: Postgres 9.5 Release Notes

#8

Dupe: http://www.postgresql.org/about/news/1636/

This post links to the release notes. The post you mention links to the press release. They contain similar but different information.

Sure, but this is about the new release — I don't see the point of having two threads about the same thing. (The press release links to the release notes, too.)

Re: Postgres 9.5 Release Notes

#9

Earlier quoted context omitted.

This post links to the release notes. The post you mention links to the press release. They contain similar but different information.

Sure, but this is about the new release — I don't see the point of having two threads about the same thing. (The press release links to the release notes, too.)

Fair point. It is reasonable to demote this post.

Personally, I always read the release notes but am less interested in the press release. I think many others prefer the opposite, hence my posting both. You raise a valid point though.

Re: Postgres 9.5 Release Notes

#10
post #3

Anyone have ever built an application utilising row level security? In old-school systems you normally have one database user and a connection pool set up in the app with that user. Row level access is handeld with join tables to sort out what data is accessible for the specific users (sent as parameter to most queries). With row-level security you would crate a db-user for each application user and also its own conn…

Connect to db from web app with one user then set role to real user: http://stackoverflow.com/questions/2998597/switch-role-after...

This allows pooling.

I made a quick app with pg 9.5 rc1, rls, spring data rest which I'm hoping to share next week.

Post reply on HN