]> granicus.if.org Git - postgresql/commit
Make security barrier views automatically updatable
authorStephen Frost <sfrost@snowman.net>
Sun, 13 Apr 2014 01:04:58 +0000 (21:04 -0400)
committerStephen Frost <sfrost@snowman.net>
Sun, 13 Apr 2014 01:04:58 +0000 (21:04 -0400)
commit842faa714c0454d67e523f5a0b6df6500e9bc1a5
tree1c65cbddbcf8ad84a8a5985a846f78622bac5f26
parent9d229f399e87d2ae7132c2e8feef317ce1479728
Make security barrier views automatically updatable

Views which are marked as security_barrier must have their quals
applied before any user-defined quals are called, to prevent
user-defined functions from being able to see rows which the
security barrier view is intended to prevent them from seeing.

Remove the restriction on security barrier views being automatically
updatable by adding a new securityQuals list to the RTE structure
which keeps track of the quals from security barrier views at each
level, independently of the user-supplied quals.  When RTEs are
later discovered which have securityQuals populated, they are turned
into subquery RTEs which are marked as security_barrier to prevent
any user-supplied quals being pushed down (modulo LEAKPROOF quals).

Dean Rasheed, reviewed by Craig Ringer, Simon Riggs, KaiGai Kohei
19 files changed:
doc/src/sgml/ref/create_view.sgml
src/backend/commands/tablecmds.c
src/backend/commands/view.c
src/backend/nodes/copyfuncs.c
src/backend/nodes/equalfuncs.c
src/backend/nodes/nodeFuncs.c
src/backend/nodes/outfuncs.c
src/backend/nodes/readfuncs.c
src/backend/optimizer/plan/planner.c
src/backend/optimizer/prep/Makefile
src/backend/optimizer/prep/prepsecurity.c [new file with mode: 0644]
src/backend/optimizer/prep/prepunion.c
src/backend/rewrite/rewriteHandler.c
src/include/nodes/parsenodes.h
src/include/optimizer/prep.h
src/include/rewrite/rewriteHandler.h
src/test/regress/expected/create_view.out
src/test/regress/expected/updatable_views.out
src/test/regress/sql/updatable_views.sql