codekingpro/portable-devtools
115k
1/*-------------------------------------------------------------------------2 *3 * rls.h4 * Header file for Row Level Security (RLS) utility commands to be used5 * with the rowsecurity feature.6 *7 * Copyright (c) 2007-2023, PostgreSQL Global Development Group8 *9 * src/include/utils/rls.h10 *11 *-------------------------------------------------------------------------12 */13#ifndef RLS_H14#define RLS_H15 16/* GUC variable */17extern PGDLLIMPORT bool row_security;18 19/*20 * Used by callers of check_enable_rls.21 *22 * RLS could be completely disabled on the tables involved in the query,23 * which is the simple case, or it may depend on the current environment24 * (the role which is running the query or the value of the row_security25 * GUC), or it might be simply enabled as usual.26 *27 * If RLS isn't on the table involved then RLS_NONE is returned to indicate28 * that we don't need to worry about invalidating the query plan for RLS29 * reasons. If RLS is on the table, but we are bypassing it for now, then30 * we return RLS_NONE_ENV to indicate that, if the environment changes,31 * we need to invalidate and replan. Finally, if RLS should be turned on32 * for the query, then we return RLS_ENABLED, which means we also need to33 * invalidate if the environment changes.34 *35 * Note that RLS_ENABLED will also be returned if noError is true36 * (indicating that the caller simply want to know if RLS should be applied37 * for this user but doesn't want an error thrown if it is; this is used38 * by other error cases where we're just trying to decide if data from the39 * table should be passed back to the user or not).40 */41enum CheckEnableRlsResult42{43 RLS_NONE,44 RLS_NONE_ENV,45 RLS_ENABLED46};47 48extern int check_enable_rls(Oid relid, Oid checkAsUser, bool noError);49 50#endif /* RLS_H */51 