Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We recommend users leverage row-level security features built into modern RDBMS so the query results only return data for a given user.

You can read more on how to do that on Postgres here https://www.2ndquadrant.com/en/blog/application-users-vs-row...



Where do you recommend this? It sounds dangerous for databases that do not implement RLS, like Mysql, MariaDb, Sqlite. I think you should highlight that very clearly somewhere.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: