↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Hooks / Permissions and object access

row_security_policy_hook_permissive

row_security_policy_hook_permissive

hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add pol…

Reading PostgreSQL 18.

Description

hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND).

Interface type
row_security_policy_hook_type
Header
src/include/rewrite/rowsecurity.h
Subsystem
Permissions and object access
Initial value
NULL (no hook installed)

C interface

typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);
extern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;

Call sites

src/backend/rewrite/rowsecurity.c:644

Core call context: src/backend/rewrite/rowsecurity.c:638–652

		}
	}

	if (row_security_policy_hook_permissive)
	{
		List	   *hook_policies =
			(*row_security_policy_hook_permissive) (cmd, relation);

		foreach(item, hook_policies)
		{
			RowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);

			if (check_role_for_policy(policy->roles, user_id))
				*permissive_policies = lappend(*permissive_policies, policy);
		}

Related entries

Documentation and source

Source build
Version
18
Build
REL_18_STABLE
Source fingerprint
753057e340da8f22e57c9a409ea7a235fd6a46bd

Compare versions

PostgreSQL 17 → 18: unchanged.

Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.

Related entries

Export JSON · Back to Hooks · Recorded in PostgreSQL 10 through 20; the first sample is not necessarily its introduction.