ALTER ROW LEVEL SECURITY POLICY

功能描述

对已存在的行访问控制策略(包括行访问控制策略的名称,行访问控制指定的用户,行访问控制的策略表达式)进行修改。

注意事项

表的所有者或管理员用户才能进行此操作。

语法格式

  1. ALTER [ ROW LEVEL SECURITY ] POLICY [ IF EXISTS ] policy_name ON table_name RENAME TO new_policy_name;
  2. ALTER [ ROW LEVEL SECURITY ] POLICY policy_name ON table_name
  3. [ TO { role_name | PUBLIC } [, ...] ]
  4. [ USING ( using_expression ) ];

参数说明

  • policy_name

    行访问控制策略名称。

  • table_name

    行访问控制策略的表名。

  • new_policy_name

    新的行访问控制策略名称。

  • role_name

    行访问控制策略应用的数据库用户,可以指定多个用户,PUBLIC表示应用到所有用户。

  • using_expression

    行访问控制的表达式,返回值为boolean类型。

示例

  1. --创建数据表all_data
  2. postgres=# CREATE TABLE all_data(id int, role varchar(100), data varchar(100));
  3. --创建行访问控制策略,当前用户只能查看用户自身的数据
  4. postgres=# CREATE ROW LEVEL SECURITY POLICY all_data_rls ON all_data USING(role = CURRENT_USER);
  5. postgres=# \d+ all_data
  6. Table "public.all_data"
  7. Column | Type | Modifiers | Storage | Stats target | Description
  8. --------+------------------------+-----------+----------+--------------+-------------
  9. id | integer | | plain | |
  10. role | character varying(100) | | extended | |
  11. data | character varying(100) | | extended | |
  12. Row Level Security Policies:
  13. POLICY "all_data_rls"
  14. USING (((role)::name = "current_user"()))
  15. Has OIDs: no
  16. Location Nodes: ALL DATANODES
  17. Options: orientation=row, compression=no
  18. --修改行访问控制all_data_rls的名称
  19. postgres=# ALTER ROW LEVEL SECURITY POLICY all_data_rls ON all_data RENAME TO all_data_new_rls;
  20. --修改行访问控制策略影响的用户
  21. postgres=# ALTER ROW LEVEL SECURITY POLICY all_data_new_rls ON all_data TO alice, bob;
  22. postgres=# \d+ all_data
  23. Table "public.all_data"
  24. Column | Type | Modifiers | Storage | Stats target | Description
  25. --------+------------------------+-----------+----------+--------------+-------------
  26. id | integer | | plain | |
  27. role | character varying(100) | | extended | |
  28. data | character varying(100) | | extended | |
  29. Row Level Security Policies:
  30. POLICY "all_data_new_rls"
  31. TO alice,bob
  32. USING (((role)::name = "current_user"()))
  33. Has OIDs: no
  34. Location Nodes: ALL DATANODES
  35. Options: orientation=row, compression=no, enable_rowsecurity=true
  36. --修改行访问控制策略表达式
  37. postgres=# ALTER ROW LEVEL SECURITY POLICY all_data_new_rls ON all_data USING (id > 100 AND role = current_user);
  38. postgres=# \d+ all_data
  39. Table "public.all_data"
  40. Column | Type | Modifiers | Storage | Stats target | Description
  41. --------+------------------------+-----------+----------+--------------+-------------
  42. id | integer | | plain | |
  43. role | character varying(100) | | extended | |
  44. data | character varying(100) | | extended | |
  45. Row Level Security Policies:
  46. POLICY "all_data_new_rls"
  47. TO alice,bob
  48. USING (((id > 100) AND ((role)::name = "current_user"())))
  49. Has OIDs: no
  50. Location Nodes: ALL DATANODES
  51. Options: orientation=row, compression=no, enable_rowsecurity=true

相关链接

CREATE ROW LEVEL SECURITY POLICYDROP ROW LEVEL SECURITY POLICY