{"Entry":{"collection":"guc","key":"row_security","name":"row_security","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Client Connection Defaults / Statement Behavior","category_zh":"","changed_in":["11","18"],"changes":[{"documentation_changed":false,"fields":{},"from":"9.4","status":"added","to":"9.5"},{"documentation_changed":false,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Client Connection Defaults / Statement Behavior"}},"from":"10","status":"changed","to":"11"},{"documentation_changed":false,"fields":{"short_desc":{"from":"Enable row security.","to":"Enables row security."}},"from":"17","status":"changed","to":"18"}],"content_hash":"66c81dbd034b69bd78d9d0480aeb3e3e6cda07479b262204e7646724799c2f1d","context":"","default_changed_in":[],"default_history":[{"from":"9.5","to":"19","value":"on"}],"editorial":{"advice":{"olap":"Use a dedicated analytical role if row_security must differ, and verify that exports, triggers, policies, and name resolution still preserve data correctness.","oltp":"Treat row_security as a correctness or security control, not a throughput knob. Grant SET authority narrowly and establish it from trusted role or application policy.","small":"Keep row_security at its safe default unless a documented repair or compatibility workflow requires otherwise; record and automatically restore temporary changes."},"mechanism":["row_security enables row security. When enabled, row security will be applied to all users. Off does not bypass policies for ordinary roles: it raises an error where a policy would apply, which lets tools such as pg_dump avoid silently incomplete results.","row_security is a USER-context setting. An authorized role can change it for a session, while ALTER ROLE or ALTER DATABASE can establish a default for future sessions.","Because session state can survive in pooled connections, role defaults, SET privilege, RESET behavior, and application checkout hooks are part of the control's effective boundary."],"pitfalls":["Changing row_security in one session and assuming role defaults, database defaults, or other pooled sessions changed with it.","Granting broad SET rights to a control that can change correctness, policy enforcement, or name resolution.","Failing to reset a security-sensitive session value before a pooled connection is reused by another request.","Setting off expecting a bypass, although ordinary roles receive an error when a policy would apply."],"references":[{"title":"PostgreSQL 19 Beta 4: row_security","url":"https://www.postgresql.org/docs/19/runtime-config-client.html#GUC-ROW-SECURITY"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["search_path","session_replication_role","event_triggers","restrict_nonsystem_relation_kind","createrole_self_grant"],"summary":"row_security is the PostgreSQL setting that controls whether PostgreSQL enables row security."},"enumvals":[],"first_version":"9.5","group":"Client Connection Defaults","group_slug":"client","imported_at":"2026-09-27T17:57:31.918814+08:00","intro_commit":{"authored_at":"2014-09-19T11:18:35-04:00","discussion":[],"hash":"491c029dbc4206779cf659aa0ff986af7831d2ff","subject":"Row-Level Security Policies (RLS)","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=491c029dbc4206779cf659aa0ff986af7831d2ff"},"key":"row_security","last_version":"20","max_val":"","min_val":"","name":"row_security","position":344,"present_in":["9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"This variable controls whether to raise an error in lieu of applying a row security policy.","short_desc_zh":"","source_rev":"english-manuals:7a42dec6903ac7fae9782c0ec38630852af93aa5e903abf0a57b9ecb99b92a2e","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"row_security","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"row_security","SourceRevision":"english-manuals:7a42dec6903ac7fae9782c0ec38630852af93aa5e903abf0a57b9ecb99b92a2e","Facts":{"boot_val":"on","category":"Client Connection Defaults / Statement Behavior","context":"user","description":"This variable controls whether to raise an error in lieu of applying a row security policy. When set to on, policies apply normally. When set to off, queries fail which would otherwise apply at least one policy. The default is on. Change to off where limited row visibility could cause incorrect results; for example, pg_dump makes that change by default. This variable has no effect on roles which bypass every row security policy, to wit, superusers and roles with the BYPASSRLS attribute. For more information on row security policies, see CREATE POLICY.","doc":{"anchor":"GUC-ROW-SECURITY","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"When enabled, row security will be applied to all users.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"row_security","short_desc":"Enables row security.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-ROW-SECURITY","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"row_security","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"row_security","Summary":"","BodyHTML":"\u003cp\u003e这个变量控制是否以抛出一个错误来代替应用一条行安全性策略。在设置为\u003ccode\u003eon\u003c/code\u003e时，策略正常应用。在设置为\u003ccode\u003eoff\u003c/code\u003e时，原本会应用至少一条策略的查询就会失败。默认为\u003ccode\u003eon\u003c/code\u003e。受限的行可见性可能导致不正确的结果时，可将其改成\u003ccode\u003eoff\u003c/code\u003e。例如，\u003cspan\u003epg_dump\u003c/span\u003e默认会做这种更改。这个变量对能绕过每一条行安全性策略的角色（即超级用户和具有\u003ccode\u003eBYPASSRLS\u003c/code\u003e属性的角色）没有效果。\u003c/p\u003e\u003cp\u003e更多关于行安全性策略的信息请见\u003ca href=\"/docs/18/sql-createpolicy.html\" title=\"CREATE POLICY\" rel=\"nofollow\"\u003e\u003cspan\u003eCREATE POLICY\u003c/span\u003e\u003c/a\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"0e8be7e9e590c1d970ed2ab847075d9f663fa6e22c03053bcc4803d9b01c16ae","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e这个变量控制是否以抛出一个错误来代替应用一条行安全性策略。在设置为\u003ccode class=\"literal\"\u003eon\u003c/code\u003e时，策略正常应用。在设置为\u003ccode class=\"literal\"\u003eoff\u003c/code\u003e时，原本会应用至少一条策略的查询就会失败。默认为\u003ccode class=\"literal\"\u003eon\u003c/code\u003e。受限的行可见性可能导致不正确的结果时，可将其改成\u003ccode class=\"literal\"\u003eoff\u003c/code\u003e。例如，\u003cspan class=\"application\"\u003epg_dump\u003c/span\u003e默认会做这种更改。这个变量对能绕过每一条行安全性策略的角色（即超级用户和具有\u003ccode class=\"literal\"\u003eBYPASSRLS\u003c/code\u003e属性的角色）没有效果。\u003c/p\u003e\u003cp\u003e更多关于行安全性策略的信息请见\u003ca href=\"/docs/18/sql-createpolicy.html\" title=\"CREATE POLICY\"\u003e\u003cspan class=\"refentrytitle\"\u003eCREATE POLICY\u003c/span\u003e\u003c/a\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
