{"kind": "hook", "major": "18", "item": {"slug": "row_security_policy_hook_permissive", "name": "row_security_policy_hook_permissive", "name_zh": "row_security_policy_hook_permissive", "category": "Permissions and object access", "summary": "hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND).", "aliases": [], "versions": {"10": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/10/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_10_STABLE", "label": "10", "major": "10", "channel": "historical", "revision": "f4e8f137bfb08a664c8288824c1e36b5143ac875"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/f4e8f137bfb08a664c8288824c1e36b5143ac875/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "07a72720388c27543f5b7565cf0eefabcc90a337ec2af3a07cdb4473220dd47d"}, {"url": "https://github.com/postgres/postgres/blob/f4e8f137bfb08a664c8288824c1e36b5143ac875/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "c406a44b5a0a36191ea6bcf77bef1c2b4d2a9bc7f94e371e5e33795a737bda9f"}, {"url": "https://github.com/postgres/postgres/blob/f4e8f137bfb08a664c8288824c1e36b5143ac875/src/backend/rewrite/rowsecurity.c#L505", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "c406a44b5a0a36191ea6bcf77bef1c2b4d2a9bc7f94e371e5e33795a737bda9f"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:505"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:499\u2013513", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "11": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/11/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_11_STABLE", "label": "11", "major": "11", "channel": "historical", "revision": "170e416034ec0231d9e9238f2577eeb76ca8d181"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/170e416034ec0231d9e9238f2577eeb76ca8d181/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "d929037d638b90ed6d219b880ce7a2ca34b1fbbe751e6ab01f51cd4a09d8aac5"}, {"url": "https://github.com/postgres/postgres/blob/170e416034ec0231d9e9238f2577eeb76ca8d181/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "2deefb312cce0c9ce009f9f606abd469df574507faccf6bb5ab789d67f4bb000"}, {"url": "https://github.com/postgres/postgres/blob/170e416034ec0231d9e9238f2577eeb76ca8d181/src/backend/rewrite/rowsecurity.c#L505", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "2deefb312cce0c9ce009f9f606abd469df574507faccf6bb5ab789d67f4bb000"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:505"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:499\u2013513", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "12": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/12/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_12_STABLE", "label": "12", "major": "12", "channel": "historical", "revision": "3f302f0ed06f69c5ebd33d4df95895323a3cbef6"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/3f302f0ed06f69c5ebd33d4df95895323a3cbef6/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "4136a6bc4fcea2811d6bd8052a1aed59259c4877f0b3615821298a3bb8fc6197"}, {"url": "https://github.com/postgres/postgres/blob/3f302f0ed06f69c5ebd33d4df95895323a3cbef6/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "c9ee16a059158502196f5669fb153872388f382a3275dc4cbaa4a90e34111859"}, {"url": "https://github.com/postgres/postgres/blob/3f302f0ed06f69c5ebd33d4df95895323a3cbef6/src/backend/rewrite/rowsecurity.c#L505", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "c9ee16a059158502196f5669fb153872388f382a3275dc4cbaa4a90e34111859"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:505"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:499\u2013513", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "13": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/13/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_13_STABLE", "label": "13", "major": "13", "channel": "historical", "revision": "05f6c9ec2c475fae8fdd56ae40bd01afcf70d1f2"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/05f6c9ec2c475fae8fdd56ae40bd01afcf70d1f2/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "331920cc72b344ccea3831b37290d2551ed0d5039793816572f8c66ce9c47faa"}, {"url": "https://github.com/postgres/postgres/blob/05f6c9ec2c475fae8fdd56ae40bd01afcf70d1f2/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "023954d3c9f688fe4b483032be19bd4c6717403008f7d0d6ec1d3860877622ff"}, {"url": "https://github.com/postgres/postgres/blob/05f6c9ec2c475fae8fdd56ae40bd01afcf70d1f2/src/backend/rewrite/rowsecurity.c#L503", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "023954d3c9f688fe4b483032be19bd4c6717403008f7d0d6ec1d3860877622ff"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:503"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:497\u2013511", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "14": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/14/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_14_STABLE", "label": "14", "major": "14", "channel": "stable", "revision": "fba35c7c28a567839faba867db0808564c0a66db"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/fba35c7c28a567839faba867db0808564c0a66db/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "6a0b1ec1b63872cdfcfcda260354c5969bd38966ff35ff0374bf424c08e6aa25"}, {"url": "https://github.com/postgres/postgres/blob/fba35c7c28a567839faba867db0808564c0a66db/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "5aaccb6b64360bf3d9d791203205cddec0c3b0ff5ec6b2fcee485ae85d45cd6c"}, {"url": "https://github.com/postgres/postgres/blob/fba35c7c28a567839faba867db0808564c0a66db/src/backend/rewrite/rowsecurity.c#L503", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "5aaccb6b64360bf3d9d791203205cddec0c3b0ff5ec6b2fcee485ae85d45cd6c"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:503"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:497\u2013511", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "15": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/15/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_15_STABLE", "label": "15", "major": "15", "channel": "stable", "revision": "0351991b8e7c7b64382e2f30ce581a8f276590a6"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/0351991b8e7c7b64382e2f30ce581a8f276590a6/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "829c9cf50f3e72b38885b310c27ef2e03d44675832de9e3ae3feec8373d89f05"}, {"url": "https://github.com/postgres/postgres/blob/0351991b8e7c7b64382e2f30ce581a8f276590a6/src/backend/rewrite/rowsecurity.c#L96", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "0ad74d267cfddab7fdd8fc5763fa30667f9ce58eef12f9d1e5a79c8f3fe80a3b"}, {"url": "https://github.com/postgres/postgres/blob/0351991b8e7c7b64382e2f30ce581a8f276590a6/src/backend/rewrite/rowsecurity.c#L634", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "0ad74d267cfddab7fdd8fc5763fa30667f9ce58eef12f9d1e5a79c8f3fe80a3b"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:634"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:628\u2013642", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "16": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/16/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_16_STABLE", "label": "16", "major": "16", "channel": "stable", "revision": "dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "0b21b9f1884d1c0417f1d27502d91a9116ea8ab14aec2aa2daf7b1ae77fc38b9"}, {"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/backend/rewrite/rowsecurity.c#L97", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "ebb45f5b2794ba860e6738824dc4a74ce9888edec109f0f9cdbea70ee0799169"}, {"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/backend/rewrite/rowsecurity.c#L641", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "ebb45f5b2794ba860e6738824dc4a74ce9888edec109f0f9cdbea70ee0799169"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:641"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:635\u2013649", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "17": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/17/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_17_STABLE", "label": "17", "major": "17", "channel": "stable", "revision": "163288afd32a448244c8df75b3c33181aadd7f20"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "e5aa6f98457bb7cb765182cf6e08ec03b3655bea20789292ff8d4682c8adc4b4"}, {"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/backend/rewrite/rowsecurity.c#L86", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "cc73950f43f4c4c6b26d98e9d184babd5f1d5d3a177336d75f5a19c9abd49851"}, {"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/backend/rewrite/rowsecurity.c#L644", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "cc73950f43f4c4c6b26d98e9d184babd5f1d5d3a177336d75f5a19c9abd49851"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:644"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:638\u2013652", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "18": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/18/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_18_STABLE", "label": "18", "major": "18", "channel": "stable", "revision": "753057e340da8f22e57c9a409ea7a235fd6a46bd"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "3b195aed12c4378146a3e74d7873676f6e7e80f18f4fe9ef6bc125ef2f9cea24"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/rewrite/rowsecurity.c#L86", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "dca1d39120cb8f5cca60caf1264de7c3b5ce6f30c1a17ce1d5a42da0be6cf75c"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/rewrite/rowsecurity.c#L644", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "dca1d39120cb8f5cca60caf1264de7c3b5ce6f30c1a17ce1d5a42da0be6cf75c"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:644"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:638\u2013652", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "19": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/19/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_19_BETA4", "label": "19 Beta 4", "major": "19", "channel": "preview", "revision": "b73d13c32c834a2c8e1c60cb92f79530376cedf1"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "30a091cdb4b8fe9166dd7c824c3f491d9d0433995667cdb1950cc023e5878e19"}, {"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/backend/rewrite/rowsecurity.c#L86", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "e635229a5bd8af566e8122e76c6636027897442614f62b49696af2f5464139a0"}, {"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/backend/rewrite/rowsecurity.c#L659", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "e635229a5bd8af566e8122e76c6636027897442614f62b49696af2f5464139a0"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:659"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:653\u2013667", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "20": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/devel/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "master", "label": "20 devel", "major": "20", "channel": "devel", "revision": "2c10c2ce4d7bcd57543a49ab402af02a39724e0a"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "30a091cdb4b8fe9166dd7c824c3f491d9d0433995667cdb1950cc023e5878e19"}, {"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/backend/rewrite/rowsecurity.c#L86", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "e635229a5bd8af566e8122e76c6636027897442614f62b49696af2f5464139a0"}, {"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/backend/rewrite/rowsecurity.c#L659", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "e635229a5bd8af566e8122e76c6636027897442614f62b49696af2f5464139a0"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:659"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:653\u2013667", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}}, "content_hash": "ef26807d10f253e7fc7572a7ab90ae1298136995c999cb90c00169759f9ecb55", "imported_at": "2026-09-27T09:57:58.857"}, "snapshot": {"facts": [{"label": "Interface type", "value": "row_security_policy_hook_type"}, {"label": "Header", "value": "src/include/rewrite/rowsecurity.h"}, {"label": "Subsystem", "value": "Permissions and object access"}, {"label": "Initial value", "value": "NULL (no hook installed)"}], "related": [{"url": "/docs/18/ddl-rowsecurity.html", "label": "Row Security Policies"}], "release": {"ref": "REL_18_STABLE", "label": "18", "major": "18", "channel": "stable", "revision": "753057e340da8f22e57c9a409ea7a235fd6a46bd"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/include/rewrite/rowsecurity.h#L37", "path": "src/include/rewrite/rowsecurity.h", "label": "Interface declaration", "sha256": "3b195aed12c4378146a3e74d7873676f6e7e80f18f4fe9ef6bc125ef2f9cea24"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/rewrite/rowsecurity.c#L86", "path": "src/backend/rewrite/rowsecurity.c", "label": "Core definition", "sha256": "dca1d39120cb8f5cca60caf1264de7c3b5ce6f30c1a17ce1d5a42da0be6cf75c"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/rewrite/rowsecurity.c#L644", "path": "src/backend/rewrite/rowsecurity.c", "label": "Call sites", "sha256": "dca1d39120cb8f5cca60caf1264de7c3b5ce6f30c1a17ce1d5a42da0be6cf75c"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/rewrite/rowsecurity.c:644"]}, {"code": "\t\t}\n\t}\n\n\tif (row_security_policy_hook_permissive)\n\t{\n\t\tList\t   *hook_policies =\n\t\t\t(*row_security_policy_hook_permissive) (cmd, relation);\n\n\t\tforeach(item, hook_policies)\n\t\t{\n\t\t\tRowSecurityPolicy *policy = (RowSecurityPolicy *) lfirst(item);\n\n\t\t\tif (check_role_for_policy(policy->roles, user_id))\n\t\t\t\t*permissive_policies = lappend(*permissive_policies, policy);\n\t\t}", "title": "Core call context: src/backend/rewrite/rowsecurity.c:638\u2013652", "paragraphs": []}], "signature": "typedef List *(*row_security_policy_hook_type) (CmdType cmdtype, Relation relation);\nextern PGDLLIMPORT row_security_policy_hook_type row_security_policy_hook_permissive;", "description": ["hooks to allow extensions to add their own security policies row_security_policy_hook_permissive can be used to add policies which are combined with the other permissive policies, using OR. row_security_policy_hook_restrictive can be used to add policies which are enforced, regardless of other policies (they are combined using AND)."]}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}