From: | PG Doc comments form <noreply(at)postgresql(dot)org> |
---|---|
To: | pgsql-docs(at)lists(dot)postgresql(dot)org |
Cc: | wstrzalka(at)gmail(dot)com |
Subject: | pg_stats entries visibility with RLS enabled |
Date: | 2023-12-08 16:45:48 |
Message-ID: | 170205394886.398198.4628897348940629963@wrigleys.postgresql.org |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-docs |
The following documentation comment has been logged on the website:
Page: https://www.postgresql.org/docs/16/view-pg-stats.html
Description:
First paragraph for the pg_stats view says: "This view allows access only to
rows of pg_statistic that correspond to tables the user has permission to
read, and therefore it is safe to allow public read access to this view."
I think it would be worth to mention that with RLS enabled for the table the
rows will also be hidden to not reveal values from the rows not visible to
the user.
Wojtek
From | Date | Subject | |
---|---|---|---|
Next Message | PG Doc comments form | 2023-12-08 17:42:27 | unclear wording re: spoofing prevention on network connections |
Previous Message | David G. Johnston | 2023-12-08 13:58:30 | Re: Where is using a table name as a "row value" documented? |