[{"data":1,"prerenderedAt":4186},["ShallowReactive",2],{"page-\u002Fsql\u002F24-security-and-roles":3},{"id":4,"title":5,"body":6,"description":4179,"extension":4180,"meta":4181,"navigation":102,"path":4182,"seo":4183,"stem":4184,"__hash__":4185},"content\u002Fsql\u002F24-security-and-roles.md","24 — Security, Roles & Permissions",{"type":7,"value":8,"toc":4156},"minimark",[9,13,31,36,50,202,207,340,344,534,538,774,778,1017,1021,1096,1100,1107,1470,1474,1542,1561,1565,1725,1729,1808,1812,1815,2761,2765,2872,2876,3055,3059,3230,3234,3467,3471,3534,3538,3694,3698,3904,3908,3911,3995,4152],[10,11,5],"h1",{"id":12},"_24-security-roles-permissions",[14,15,16,17,21,22,26,27,30],"p",{},"Database security is ",[18,19,20],"strong",{},"least privilege",": every role gets exactly the access it needs, no more. Over-broad grants (",[23,24,25],"code",{},"GRANT ALL","), superuser app connections, and missing ",[23,28,29],{},"DEFAULT PRIVILEGES"," are how data leaks and breaches happen. PostgreSQL's security model is role-based with table\u002Fcolumn\u002Frow-level granularity.",[32,33,35],"h2",{"id":34},"roles-users-and-groups-are-the-same-thing","Roles — users and groups are the same thing",[14,37,38,39,42,43,46,47,49],{},"PostgreSQL uses ",[18,40,41],{},"roles"," for both users and groups. A role with the ",[23,44,45],{},"LOGIN"," attribute is a \"user\" (can connect); without ",[23,48,45],{},", it's a \"group\" (exists only for privilege inheritance).",[51,52,54],"code-wrapper",{"language":53},"sql",[55,56,60],"pre",{"className":57,"code":58,"language":53,"meta":59,"style":59},"language-sql shiki shiki-themes github-light github-dark","-- A login role (a \"user\") — has LOGIN + PASSWORD\nCREATE ROLE alice LOGIN PASSWORD 'secret_passphrase_here';\n\n-- A group role (no LOGIN) — exists only for privilege inheritance\nCREATE ROLE analytics_team;\n\n-- Add alice to the group (alice INHERITS the group's privileges by default)\nGRANT analytics_team TO alice;\n\n-- Grant privileges to the GROUP, not to alice directly\nGRANT SELECT ON ALL TABLES IN SCHEMA reporting TO analytics_team;\n-- Now alice inherits SELECT on reporting tables via analytics_team.\n-- To remove alice's access: REVOKE analytics_team FROM alice (one command,\n-- not per-table). This is O(teams) management, not O(users × tables).\n","",[23,61,62,71,97,104,110,120,125,131,146,151,157,184,190,196],{"__ignoreMap":59},[63,64,67],"span",{"class":65,"line":66},"line",1,[63,68,70],{"class":69},"sdCPZ","-- A login role (a \"user\") — has LOGIN + PASSWORD\n",[63,72,74,78,81,85,87,90,94],{"class":65,"line":73},2,[63,75,77],{"class":76},"svdQ7","CREATE",[63,79,80],{"class":76}," ROLE",[63,82,84],{"class":83},"ssxIu"," alice ",[63,86,45],{"class":76},[63,88,89],{"class":76}," PASSWORD",[63,91,93],{"class":92},"sJ6F3"," 'secret_passphrase_here'",[63,95,96],{"class":83},";\n",[63,98,100],{"class":65,"line":99},3,[63,101,103],{"emptyLinePlaceholder":102},true,"\n",[63,105,107],{"class":65,"line":106},4,[63,108,109],{"class":69},"-- A group role (no LOGIN) — exists only for privilege inheritance\n",[63,111,113,115,117],{"class":65,"line":112},5,[63,114,77],{"class":76},[63,116,80],{"class":76},[63,118,119],{"class":83}," analytics_team;\n",[63,121,123],{"class":65,"line":122},6,[63,124,103],{"emptyLinePlaceholder":102},[63,126,128],{"class":65,"line":127},7,[63,129,130],{"class":69},"-- Add alice to the group (alice INHERITS the group's privileges by default)\n",[63,132,134,137,140,143],{"class":65,"line":133},8,[63,135,136],{"class":76},"GRANT",[63,138,139],{"class":83}," analytics_team ",[63,141,142],{"class":76},"TO",[63,144,145],{"class":83}," alice;\n",[63,147,149],{"class":65,"line":148},9,[63,150,103],{"emptyLinePlaceholder":102},[63,152,154],{"class":65,"line":153},10,[63,155,156],{"class":69},"-- Grant privileges to the GROUP, not to alice directly\n",[63,158,160,162,165,168,171,174,177,180,182],{"class":65,"line":159},11,[63,161,136],{"class":76},[63,163,164],{"class":76}," SELECT",[63,166,167],{"class":76}," ON",[63,169,170],{"class":83}," ALL TABLES ",[63,172,173],{"class":76},"IN",[63,175,176],{"class":76}," SCHEMA",[63,178,179],{"class":83}," reporting ",[63,181,142],{"class":76},[63,183,119],{"class":83},[63,185,187],{"class":65,"line":186},12,[63,188,189],{"class":69},"-- Now alice inherits SELECT on reporting tables via analytics_team.\n",[63,191,193],{"class":65,"line":192},13,[63,194,195],{"class":69},"-- To remove alice's access: REVOKE analytics_team FROM alice (one command,\n",[63,197,199],{"class":65,"line":198},14,[63,200,201],{"class":69},"-- not per-table). This is O(teams) management, not O(users × tables).\n",[203,204,206],"h3",{"id":205},"role-attributes","Role attributes",[51,208,209],{"language":53},[55,210,212],{"className":57,"code":211,"language":53,"meta":59,"style":59},"CREATE ROLE app_user LOGIN PASSWORD '...' NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION;\n-- LOGIN: can connect\n-- SUPERUSER: bypasses ALL permission checks (dangerous — avoid for apps)\n-- CREATEDB: can create databases\n-- CREATEROLE: can create\u002Fdrop roles\n-- REPLICATION: can stream replication\n-- BYPASSRLS: bypasses Row-Level Security (dangerous for app roles)\n-- CONNECTION LIMIT n: max concurrent connections for this role\n-- VALID UNTIL 'timestamp': password expiry\n\nALTER ROLE app_user CONNECTION LIMIT 50;          -- pool size cap\nALTER ROLE alice VALID UNTIL '2026-12-31';        -- password expires\nALTER ROLE alice PASSWORD 'new_passphrase';       -- rotate password\n",[23,213,214,233,238,243,248,253,258,263,268,273,277,302,320],{"__ignoreMap":59},[63,215,216,218,220,223,225,227,230],{"class":65,"line":66},[63,217,77],{"class":76},[63,219,80],{"class":76},[63,221,222],{"class":83}," app_user ",[63,224,45],{"class":76},[63,226,89],{"class":76},[63,228,229],{"class":92}," '...'",[63,231,232],{"class":83}," NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION;\n",[63,234,235],{"class":65,"line":73},[63,236,237],{"class":69},"-- LOGIN: can connect\n",[63,239,240],{"class":65,"line":99},[63,241,242],{"class":69},"-- SUPERUSER: bypasses ALL permission checks (dangerous — avoid for apps)\n",[63,244,245],{"class":65,"line":106},[63,246,247],{"class":69},"-- CREATEDB: can create databases\n",[63,249,250],{"class":65,"line":112},[63,251,252],{"class":69},"-- CREATEROLE: can create\u002Fdrop roles\n",[63,254,255],{"class":65,"line":122},[63,256,257],{"class":69},"-- REPLICATION: can stream replication\n",[63,259,260],{"class":65,"line":127},[63,261,262],{"class":69},"-- BYPASSRLS: bypasses Row-Level Security (dangerous for app roles)\n",[63,264,265],{"class":65,"line":133},[63,266,267],{"class":69},"-- CONNECTION LIMIT n: max concurrent connections for this role\n",[63,269,270],{"class":65,"line":148},[63,271,272],{"class":69},"-- VALID UNTIL 'timestamp': password expiry\n",[63,274,275],{"class":65,"line":153},[63,276,103],{"emptyLinePlaceholder":102},[63,278,279,282,284,286,289,292,296,299],{"class":65,"line":159},[63,280,281],{"class":76},"ALTER",[63,283,80],{"class":76},[63,285,222],{"class":83},[63,287,288],{"class":76},"CONNECTION",[63,290,291],{"class":76}," LIMIT",[63,293,295],{"class":294},"snvgF"," 50",[63,297,298],{"class":83},";          ",[63,300,301],{"class":69},"-- pool size cap\n",[63,303,304,306,308,311,314,317],{"class":65,"line":186},[63,305,281],{"class":76},[63,307,80],{"class":76},[63,309,310],{"class":83}," alice VALID UNTIL ",[63,312,313],{"class":92},"'2026-12-31'",[63,315,316],{"class":83},";        ",[63,318,319],{"class":69},"-- password expires\n",[63,321,322,324,326,328,331,334,337],{"class":65,"line":192},[63,323,281],{"class":76},[63,325,80],{"class":76},[63,327,84],{"class":83},[63,329,330],{"class":76},"PASSWORD",[63,332,333],{"class":92}," 'new_passphrase'",[63,335,336],{"class":83},";       ",[63,338,339],{"class":69},"-- rotate password\n",[32,341,343],{"id":342},"privileges-the-complete-table","Privileges — the complete table",[345,346,347,363],"table",{},[348,349,350],"thead",{},[351,352,353,357,360],"tr",{},[354,355,356],"th",{},"Privilege",[354,358,359],{},"Object",[354,361,362],{},"Meaning",[364,365,366,380,393,405,418,430,442,454,466,479,491,508,521],"tbody",{},[351,367,368,374,377],{},[369,370,371],"td",{},[23,372,373],{},"SELECT",[369,375,376],{},"Table, view, column",[369,378,379],{},"Read rows (or specific columns)",[351,381,382,387,390],{},[369,383,384],{},[23,385,386],{},"INSERT",[369,388,389],{},"Table, column",[369,391,392],{},"Insert rows",[351,394,395,400,402],{},[369,396,397],{},[23,398,399],{},"UPDATE",[369,401,389],{},[369,403,404],{},"Update rows",[351,406,407,412,415],{},[369,408,409],{},[23,410,411],{},"DELETE",[369,413,414],{},"Table",[369,416,417],{},"Delete rows",[351,419,420,425,427],{},[369,421,422],{},[23,423,424],{},"TRUNCATE",[369,426,414],{},[369,428,429],{},"Truncate the table",[351,431,432,437,439],{},[369,433,434],{},[23,435,436],{},"REFERENCES",[369,438,389],{},[369,440,441],{},"Create FK to this table\u002Fcolumn",[351,443,444,449,451],{},[369,445,446],{},[23,447,448],{},"TRIGGER",[369,450,414],{},[369,452,453],{},"Create triggers on this table",[351,455,456,460,463],{},[369,457,458],{},[23,459,77],{},[369,461,462],{},"Schema, database",[369,464,465],{},"Create objects in it",[351,467,468,473,476],{},[369,469,470],{},[23,471,472],{},"CONNECT",[369,474,475],{},"Database",[369,477,478],{},"Connect to the database",[351,480,481,486,488],{},[369,482,483],{},[23,484,485],{},"TEMPORARY",[369,487,475],{},[369,489,490],{},"Create temp tables",[351,492,493,498,501],{},[369,494,495],{},[23,496,497],{},"USAGE",[369,499,500],{},"Schema, sequence, FDW, type",[369,502,503,504,507],{},"Use the schema \u002F ",[23,505,506],{},"nextval"," \u002F connect \u002F use type",[351,509,510,515,518],{},[369,511,512],{},[23,513,514],{},"EXECUTE",[369,516,517],{},"Function, procedure",[369,519,520],{},"Call it",[351,522,523,528,531],{},[369,524,525],{},[23,526,527],{},"MAINTAIN",[369,529,530],{},"Table (PG 17+)",[369,532,533],{},"Run VACUUM, ANALYZE, etc.",[32,535,537],{"id":536},"grant-and-revoke","GRANT and REVOKE",[51,539,540],{"language":53},[55,541,543],{"className":57,"code":542,"language":53,"meta":59,"style":59},"-- Grant on a specific table\nGRANT SELECT, INSERT, UPDATE ON orders TO app_role;\n-- app_role can read, insert, and update orders, but NOT delete or truncate\n\n-- Grant with GRANT OPTION: the grantee can grant this privilege to others\nGRANT SELECT ON orders TO alice WITH GRANT OPTION;\n-- alice can now: GRANT SELECT ON orders TO bob;\n-- Use sparingly — this spreads authorization power unpredictably.\n\n-- Grant on all current tables in a schema (snapshot — applies to EXISTING tables only)\nGRANT SELECT ON ALL TABLES IN SCHEMA public TO analytics_team;\n\n-- Grant on all sequences in a schema\nGRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public TO app_role;\n-- USAGE: needed for nextval(). SELECT: needed for currval().\n-- Without USAGE on the sequence, INSERT into a table with a SERIAL\u002FIDENTITY\n-- column fails — the user can't call nextval on the sequence.\n\n-- Revoke\nREVOKE INSERT ON orders FROM app_role;\nREVOKE ALL ON orders FROM app_role;           -- remove all privileges\nREVOKE SELECT ON orders FROM alice CASCADE;   -- also revokes grants alice made\n",[23,544,545,550,575,580,584,589,614,619,624,628,633,654,658,663,687,693,699,705,710,716,734,755],{"__ignoreMap":59},[63,546,547],{"class":65,"line":66},[63,548,549],{"class":69},"-- Grant on a specific table\n",[63,551,552,554,556,559,561,563,565,567,570,572],{"class":65,"line":73},[63,553,136],{"class":76},[63,555,164],{"class":76},[63,557,558],{"class":83},", ",[63,560,386],{"class":76},[63,562,558],{"class":83},[63,564,399],{"class":76},[63,566,167],{"class":76},[63,568,569],{"class":83}," orders ",[63,571,142],{"class":76},[63,573,574],{"class":83}," app_role;\n",[63,576,577],{"class":65,"line":99},[63,578,579],{"class":69},"-- app_role can read, insert, and update orders, but NOT delete or truncate\n",[63,581,582],{"class":65,"line":106},[63,583,103],{"emptyLinePlaceholder":102},[63,585,586],{"class":65,"line":112},[63,587,588],{"class":69},"-- Grant with GRANT OPTION: the grantee can grant this privilege to others\n",[63,590,591,593,595,597,599,601,603,606,609,612],{"class":65,"line":122},[63,592,136],{"class":76},[63,594,164],{"class":76},[63,596,167],{"class":76},[63,598,569],{"class":83},[63,600,142],{"class":76},[63,602,84],{"class":83},[63,604,605],{"class":76},"WITH",[63,607,608],{"class":76}," GRANT",[63,610,611],{"class":76}," OPTION",[63,613,96],{"class":83},[63,615,616],{"class":65,"line":127},[63,617,618],{"class":69},"-- alice can now: GRANT SELECT ON orders TO bob;\n",[63,620,621],{"class":65,"line":133},[63,622,623],{"class":69},"-- Use sparingly — this spreads authorization power unpredictably.\n",[63,625,626],{"class":65,"line":148},[63,627,103],{"emptyLinePlaceholder":102},[63,629,630],{"class":65,"line":153},[63,631,632],{"class":69},"-- Grant on all current tables in a schema (snapshot — applies to EXISTING tables only)\n",[63,634,635,637,639,641,643,645,647,650,652],{"class":65,"line":159},[63,636,136],{"class":76},[63,638,164],{"class":76},[63,640,167],{"class":76},[63,642,170],{"class":83},[63,644,173],{"class":76},[63,646,176],{"class":76},[63,648,649],{"class":83}," public ",[63,651,142],{"class":76},[63,653,119],{"class":83},[63,655,656],{"class":65,"line":186},[63,657,103],{"emptyLinePlaceholder":102},[63,659,660],{"class":65,"line":192},[63,661,662],{"class":69},"-- Grant on all sequences in a schema\n",[63,664,665,667,670,672,674,677,679,681,683,685],{"class":65,"line":198},[63,666,136],{"class":76},[63,668,669],{"class":83}," USAGE, ",[63,671,373],{"class":76},[63,673,167],{"class":76},[63,675,676],{"class":83}," ALL SEQUENCES ",[63,678,173],{"class":76},[63,680,176],{"class":76},[63,682,649],{"class":83},[63,684,142],{"class":76},[63,686,574],{"class":83},[63,688,690],{"class":65,"line":689},15,[63,691,692],{"class":69},"-- USAGE: needed for nextval(). SELECT: needed for currval().\n",[63,694,696],{"class":65,"line":695},16,[63,697,698],{"class":69},"-- Without USAGE on the sequence, INSERT into a table with a SERIAL\u002FIDENTITY\n",[63,700,702],{"class":65,"line":701},17,[63,703,704],{"class":69},"-- column fails — the user can't call nextval on the sequence.\n",[63,706,708],{"class":65,"line":707},18,[63,709,103],{"emptyLinePlaceholder":102},[63,711,713],{"class":65,"line":712},19,[63,714,715],{"class":69},"-- Revoke\n",[63,717,719,722,725,727,729,732],{"class":65,"line":718},20,[63,720,721],{"class":76},"REVOKE",[63,723,724],{"class":76}," INSERT",[63,726,167],{"class":76},[63,728,569],{"class":83},[63,730,731],{"class":76},"FROM",[63,733,574],{"class":83},[63,735,737,739,742,745,747,749,752],{"class":65,"line":736},21,[63,738,721],{"class":76},[63,740,741],{"class":83}," ALL ",[63,743,744],{"class":76},"ON",[63,746,569],{"class":83},[63,748,731],{"class":76},[63,750,751],{"class":83}," app_role;           ",[63,753,754],{"class":69},"-- remove all privileges\n",[63,756,758,760,762,764,766,768,771],{"class":65,"line":757},22,[63,759,721],{"class":76},[63,761,164],{"class":76},[63,763,167],{"class":76},[63,765,569],{"class":83},[63,767,731],{"class":76},[63,769,770],{"class":83}," alice CASCADE;   ",[63,772,773],{"class":69},"-- also revokes grants alice made\n",[32,775,777],{"id":776},"default-privileges-grants-on-future-objects","DEFAULT PRIVILEGES — grants on future objects",[51,779,780],{"language":53},[55,781,783],{"className":57,"code":782,"language":53,"meta":59,"style":59},"-- GRANT ON ALL TABLES applies to EXISTING tables only. New tables created\n-- after the grant are NOT covered — the creator owns them, and no one else\n-- has access until you grant explicitly. This is a common \"new table is\n-- invisible to the app\" bug.\n\n-- DEFAULT PRIVILEGES: grants that apply to FUTURE objects created by a\n-- specified role. The most important security pattern in PostgreSQL.\nALTER DEFAULT PRIVILEGES IN SCHEMA public\n  GRANT SELECT, INSERT, UPDATE ON TABLES TO app_role;\n\nALTER DEFAULT PRIVILEGES IN SCHEMA public\n  GRANT USAGE, SELECT ON SEQUENCES TO app_role;\n\n-- Now any table created in `public` by the role (specified implicitly as\n-- current_user) automatically gets these grants. No more \"forgot to grant\n-- on the new table\" outages.\n\n-- Per-creator: DEFAULT PRIVILEGES are scoped to the creator.\n-- If alice and bob both create tables, you need DEFAULT PRIVILEGES\n-- for EACH creator:\nALTER DEFAULT PRIVILEGES FOR ROLE alice IN SCHEMA public\n  GRANT SELECT ON TABLES TO analytics_team;\nALTER DEFAULT PRIVILEGES FOR ROLE bob IN SCHEMA public\n  GRANT SELECT ON TABLES TO analytics_team;\n-- Or: use a single migration role that creates all tables, and set\n-- DEFAULT PRIVILEGES for that role only.\n",[23,784,785,790,795,800,805,809,814,819,836,860,864,878,895,899,904,909,914,918,923,928,933,954,968,990,1005,1011],{"__ignoreMap":59},[63,786,787],{"class":65,"line":66},[63,788,789],{"class":69},"-- GRANT ON ALL TABLES applies to EXISTING tables only. New tables created\n",[63,791,792],{"class":65,"line":73},[63,793,794],{"class":69},"-- after the grant are NOT covered — the creator owns them, and no one else\n",[63,796,797],{"class":65,"line":99},[63,798,799],{"class":69},"-- has access until you grant explicitly. This is a common \"new table is\n",[63,801,802],{"class":65,"line":106},[63,803,804],{"class":69},"-- invisible to the app\" bug.\n",[63,806,807],{"class":65,"line":112},[63,808,103],{"emptyLinePlaceholder":102},[63,810,811],{"class":65,"line":122},[63,812,813],{"class":69},"-- DEFAULT PRIVILEGES: grants that apply to FUTURE objects created by a\n",[63,815,816],{"class":65,"line":127},[63,817,818],{"class":69},"-- specified role. The most important security pattern in PostgreSQL.\n",[63,820,821,823,826,829,831,833],{"class":65,"line":133},[63,822,281],{"class":76},[63,824,825],{"class":76}," DEFAULT",[63,827,828],{"class":83}," PRIVILEGES ",[63,830,173],{"class":76},[63,832,176],{"class":76},[63,834,835],{"class":83}," public\n",[63,837,838,841,843,845,847,849,851,853,856,858],{"class":65,"line":148},[63,839,840],{"class":76},"  GRANT",[63,842,164],{"class":76},[63,844,558],{"class":83},[63,846,386],{"class":76},[63,848,558],{"class":83},[63,850,399],{"class":76},[63,852,167],{"class":76},[63,854,855],{"class":83}," TABLES ",[63,857,142],{"class":76},[63,859,574],{"class":83},[63,861,862],{"class":65,"line":153},[63,863,103],{"emptyLinePlaceholder":102},[63,865,866,868,870,872,874,876],{"class":65,"line":159},[63,867,281],{"class":76},[63,869,825],{"class":76},[63,871,828],{"class":83},[63,873,173],{"class":76},[63,875,176],{"class":76},[63,877,835],{"class":83},[63,879,880,882,884,886,888,891,893],{"class":65,"line":186},[63,881,840],{"class":76},[63,883,669],{"class":83},[63,885,373],{"class":76},[63,887,167],{"class":76},[63,889,890],{"class":83}," SEQUENCES ",[63,892,142],{"class":76},[63,894,574],{"class":83},[63,896,897],{"class":65,"line":192},[63,898,103],{"emptyLinePlaceholder":102},[63,900,901],{"class":65,"line":198},[63,902,903],{"class":69},"-- Now any table created in `public` by the role (specified implicitly as\n",[63,905,906],{"class":65,"line":689},[63,907,908],{"class":69},"-- current_user) automatically gets these grants. No more \"forgot to grant\n",[63,910,911],{"class":65,"line":695},[63,912,913],{"class":69},"-- on the new table\" outages.\n",[63,915,916],{"class":65,"line":701},[63,917,103],{"emptyLinePlaceholder":102},[63,919,920],{"class":65,"line":707},[63,921,922],{"class":69},"-- Per-creator: DEFAULT PRIVILEGES are scoped to the creator.\n",[63,924,925],{"class":65,"line":712},[63,926,927],{"class":69},"-- If alice and bob both create tables, you need DEFAULT PRIVILEGES\n",[63,929,930],{"class":65,"line":718},[63,931,932],{"class":69},"-- for EACH creator:\n",[63,934,935,937,939,941,944,946,948,950,952],{"class":65,"line":736},[63,936,281],{"class":76},[63,938,825],{"class":76},[63,940,828],{"class":83},[63,942,943],{"class":76},"FOR",[63,945,80],{"class":76},[63,947,84],{"class":83},[63,949,173],{"class":76},[63,951,176],{"class":76},[63,953,835],{"class":83},[63,955,956,958,960,962,964,966],{"class":65,"line":757},[63,957,840],{"class":76},[63,959,164],{"class":76},[63,961,167],{"class":76},[63,963,855],{"class":83},[63,965,142],{"class":76},[63,967,119],{"class":83},[63,969,971,973,975,977,979,981,984,986,988],{"class":65,"line":970},23,[63,972,281],{"class":76},[63,974,825],{"class":76},[63,976,828],{"class":83},[63,978,943],{"class":76},[63,980,80],{"class":76},[63,982,983],{"class":83}," bob ",[63,985,173],{"class":76},[63,987,176],{"class":76},[63,989,835],{"class":83},[63,991,993,995,997,999,1001,1003],{"class":65,"line":992},24,[63,994,840],{"class":76},[63,996,164],{"class":76},[63,998,167],{"class":76},[63,1000,855],{"class":83},[63,1002,142],{"class":76},[63,1004,119],{"class":83},[63,1006,1008],{"class":65,"line":1007},25,[63,1009,1010],{"class":69},"-- Or: use a single migration role that creates all tables, and set\n",[63,1012,1014],{"class":65,"line":1013},26,[63,1015,1016],{"class":69},"-- DEFAULT PRIVILEGES for that role only.\n",[32,1018,1020],{"id":1019},"column-level-privileges-pii-protection","Column-Level Privileges — PII protection",[51,1022,1023],{"language":53},[55,1024,1026],{"className":57,"code":1025,"language":53,"meta":59,"style":59},"-- Grant access to only some columns (protect PII like salary, ssn)\nGRANT SELECT (id, name, email, department) ON employees TO analytics_team;\n-- analytics_team can SELECT id, name, email, department but NOT salary, ssn.\n-- SELECT * FROM employees → ERROR: permission denied for table employees\n-- SELECT id, name FROM employees → OK\n\n-- Column-level grants are fiddly:\n-- 1. SELECT * is denied (it includes un-granted columns)\n-- 2. Views are usually a cleaner alternative (expose only safe columns)\n-- 3. Column grants don't restrict ROWS — combine with RLS for row + column\n",[23,1027,1028,1033,1057,1062,1067,1072,1076,1081,1086,1091],{"__ignoreMap":59},[63,1029,1030],{"class":65,"line":66},[63,1031,1032],{"class":69},"-- Grant access to only some columns (protect PII like salary, ssn)\n",[63,1034,1035,1037,1039,1042,1045,1048,1050,1053,1055],{"class":65,"line":73},[63,1036,136],{"class":76},[63,1038,164],{"class":76},[63,1040,1041],{"class":83}," (id, ",[63,1043,1044],{"class":76},"name",[63,1046,1047],{"class":83},", email, department) ",[63,1049,744],{"class":76},[63,1051,1052],{"class":83}," employees ",[63,1054,142],{"class":76},[63,1056,119],{"class":83},[63,1058,1059],{"class":65,"line":99},[63,1060,1061],{"class":69},"-- analytics_team can SELECT id, name, email, department but NOT salary, ssn.\n",[63,1063,1064],{"class":65,"line":106},[63,1065,1066],{"class":69},"-- SELECT * FROM employees → ERROR: permission denied for table employees\n",[63,1068,1069],{"class":65,"line":112},[63,1070,1071],{"class":69},"-- SELECT id, name FROM employees → OK\n",[63,1073,1074],{"class":65,"line":122},[63,1075,103],{"emptyLinePlaceholder":102},[63,1077,1078],{"class":65,"line":127},[63,1079,1080],{"class":69},"-- Column-level grants are fiddly:\n",[63,1082,1083],{"class":65,"line":133},[63,1084,1085],{"class":69},"-- 1. SELECT * is denied (it includes un-granted columns)\n",[63,1087,1088],{"class":65,"line":148},[63,1089,1090],{"class":69},"-- 2. Views are usually a cleaner alternative (expose only safe columns)\n",[63,1092,1093],{"class":65,"line":153},[63,1094,1095],{"class":69},"-- 3. Column grants don't restrict ROWS — combine with RLS for row + column\n",[32,1097,1099],{"id":1098},"row-level-security-rls-database-enforced-row-filtering","Row-Level Security (RLS) — database-enforced row filtering",[14,1101,1102,1103,1106],{},"RLS adds a predicate to every query on a table. It's database-enforced — the application can't bypass it (unless the role has ",[23,1104,1105],{},"BYPASSRLS"," or is the table owner\u002Fsuperuser).",[51,1108,1109],{"language":53},[55,1110,1112],{"className":57,"code":1111,"language":53,"meta":59,"style":59},"-- Enable RLS on the orders table\nALTER TABLE orders ENABLE ROW LEVEL SECURITY;\n-- By default: NO policies exist → ALL access is DENIED (deny-by-default).\n-- Without a policy, even the table owner can't SELECT (unless FORCE RLS\n-- is off — the owner bypasses by default, see below).\n\n-- A SELECT policy: users can see only their own orders\nCREATE POLICY own_orders ON orders\n  FOR SELECT\n  TO authenticated_users                    -- applies to this role only\n  USING (user_id = current_setting('app.user_id')::bigint);\n  -- USING: the predicate added to SELECT\u002FUPDATE\u002FDELETE.\n  -- Every SELECT on orders gets: WHERE user_id = current_setting('app.user_id')\n  -- The user CANNOT see rows where user_id doesn't match — enforced by the DB.\n\n-- An INSERT policy: users can insert only their own orders\nCREATE POLICY insert_own_orders ON orders\n  FOR INSERT\n  TO authenticated_users\n  WITH CHECK (user_id = current_setting('app.user_id')::bigint);\n  -- WITH CHECK: the predicate validated on INSERT\u002FUPDATE.\n  -- A user can't insert an order with a different user_id.\n\n-- An UPDATE policy: users can update only their own orders\nCREATE POLICY update_own_orders ON orders\n  FOR UPDATE\n  TO authenticated_users\n  USING (user_id = current_setting('app.user_id')::bigint)         -- can SEE the row\n  WITH CHECK (user_id = current_setting('app.user_id')::bigint);   -- can SET these values\n  -- USING: which rows are visible (the user can only update rows they can see)\n  -- WITH CHECK: what the new values can be (can't reassign to another user)\n\n-- A DELETE policy: users can delete only their own orders\nCREATE POLICY delete_own_orders ON orders\n  FOR DELETE\n  TO authenticated_users\n  USING (user_id = current_setting('app.user_id')::bigint);\n  -- DELETE uses USING (which rows are visible for deletion). No WITH CHECK.\n",[23,1113,1114,1119,1142,1147,1152,1157,1161,1166,1181,1189,1200,1226,1231,1236,1241,1245,1250,1263,1270,1277,1299,1304,1309,1313,1318,1331,1338,1345,1368,1393,1399,1405,1410,1416,1430,1438,1445,1464],{"__ignoreMap":59},[63,1115,1116],{"class":65,"line":66},[63,1117,1118],{"class":69},"-- Enable RLS on the orders table\n",[63,1120,1121,1123,1126,1128,1131,1134,1137,1140],{"class":65,"line":73},[63,1122,281],{"class":76},[63,1124,1125],{"class":76}," TABLE",[63,1127,569],{"class":83},[63,1129,1130],{"class":76},"ENABLE",[63,1132,1133],{"class":76}," ROW",[63,1135,1136],{"class":76}," LEVEL",[63,1138,1139],{"class":76}," SECURITY",[63,1141,96],{"class":83},[63,1143,1144],{"class":65,"line":99},[63,1145,1146],{"class":69},"-- By default: NO policies exist → ALL access is DENIED (deny-by-default).\n",[63,1148,1149],{"class":65,"line":106},[63,1150,1151],{"class":69},"-- Without a policy, even the table owner can't SELECT (unless FORCE RLS\n",[63,1153,1154],{"class":65,"line":112},[63,1155,1156],{"class":69},"-- is off — the owner bypasses by default, see below).\n",[63,1158,1159],{"class":65,"line":122},[63,1160,103],{"emptyLinePlaceholder":102},[63,1162,1163],{"class":65,"line":127},[63,1164,1165],{"class":69},"-- A SELECT policy: users can see only their own orders\n",[63,1167,1168,1170,1173,1176,1178],{"class":65,"line":133},[63,1169,77],{"class":76},[63,1171,1172],{"class":76}," POLICY",[63,1174,1175],{"class":83}," own_orders ",[63,1177,744],{"class":76},[63,1179,1180],{"class":83}," orders\n",[63,1182,1183,1186],{"class":65,"line":148},[63,1184,1185],{"class":76},"  FOR",[63,1187,1188],{"class":76}," SELECT\n",[63,1190,1191,1194,1197],{"class":65,"line":153},[63,1192,1193],{"class":76},"  TO",[63,1195,1196],{"class":83}," authenticated_users                    ",[63,1198,1199],{"class":69},"-- applies to this role only\n",[63,1201,1202,1205,1208,1211,1214,1217,1220,1223],{"class":65,"line":159},[63,1203,1204],{"class":76},"  USING",[63,1206,1207],{"class":83}," (user_id ",[63,1209,1210],{"class":76},"=",[63,1212,1213],{"class":83}," current_setting(",[63,1215,1216],{"class":92},"'app.user_id'",[63,1218,1219],{"class":83},")::",[63,1221,1222],{"class":76},"bigint",[63,1224,1225],{"class":83},");\n",[63,1227,1228],{"class":65,"line":186},[63,1229,1230],{"class":69},"  -- USING: the predicate added to SELECT\u002FUPDATE\u002FDELETE.\n",[63,1232,1233],{"class":65,"line":192},[63,1234,1235],{"class":69},"  -- Every SELECT on orders gets: WHERE user_id = current_setting('app.user_id')\n",[63,1237,1238],{"class":65,"line":198},[63,1239,1240],{"class":69},"  -- The user CANNOT see rows where user_id doesn't match — enforced by the DB.\n",[63,1242,1243],{"class":65,"line":689},[63,1244,103],{"emptyLinePlaceholder":102},[63,1246,1247],{"class":65,"line":695},[63,1248,1249],{"class":69},"-- An INSERT policy: users can insert only their own orders\n",[63,1251,1252,1254,1256,1259,1261],{"class":65,"line":701},[63,1253,77],{"class":76},[63,1255,1172],{"class":76},[63,1257,1258],{"class":83}," insert_own_orders ",[63,1260,744],{"class":76},[63,1262,1180],{"class":83},[63,1264,1265,1267],{"class":65,"line":707},[63,1266,1185],{"class":76},[63,1268,1269],{"class":76}," INSERT\n",[63,1271,1272,1274],{"class":65,"line":712},[63,1273,1193],{"class":76},[63,1275,1276],{"class":83}," authenticated_users\n",[63,1278,1279,1282,1285,1287,1289,1291,1293,1295,1297],{"class":65,"line":718},[63,1280,1281],{"class":76},"  WITH",[63,1283,1284],{"class":76}," CHECK",[63,1286,1207],{"class":83},[63,1288,1210],{"class":76},[63,1290,1213],{"class":83},[63,1292,1216],{"class":92},[63,1294,1219],{"class":83},[63,1296,1222],{"class":76},[63,1298,1225],{"class":83},[63,1300,1301],{"class":65,"line":736},[63,1302,1303],{"class":69},"  -- WITH CHECK: the predicate validated on INSERT\u002FUPDATE.\n",[63,1305,1306],{"class":65,"line":757},[63,1307,1308],{"class":69},"  -- A user can't insert an order with a different user_id.\n",[63,1310,1311],{"class":65,"line":970},[63,1312,103],{"emptyLinePlaceholder":102},[63,1314,1315],{"class":65,"line":992},[63,1316,1317],{"class":69},"-- An UPDATE policy: users can update only their own orders\n",[63,1319,1320,1322,1324,1327,1329],{"class":65,"line":1007},[63,1321,77],{"class":76},[63,1323,1172],{"class":76},[63,1325,1326],{"class":83}," update_own_orders ",[63,1328,744],{"class":76},[63,1330,1180],{"class":83},[63,1332,1333,1335],{"class":65,"line":1013},[63,1334,1185],{"class":76},[63,1336,1337],{"class":76}," UPDATE\n",[63,1339,1341,1343],{"class":65,"line":1340},27,[63,1342,1193],{"class":76},[63,1344,1276],{"class":83},[63,1346,1348,1350,1352,1354,1356,1358,1360,1362,1365],{"class":65,"line":1347},28,[63,1349,1204],{"class":76},[63,1351,1207],{"class":83},[63,1353,1210],{"class":76},[63,1355,1213],{"class":83},[63,1357,1216],{"class":92},[63,1359,1219],{"class":83},[63,1361,1222],{"class":76},[63,1363,1364],{"class":83},")         ",[63,1366,1367],{"class":69},"-- can SEE the row\n",[63,1369,1371,1373,1375,1377,1379,1381,1383,1385,1387,1390],{"class":65,"line":1370},29,[63,1372,1281],{"class":76},[63,1374,1284],{"class":76},[63,1376,1207],{"class":83},[63,1378,1210],{"class":76},[63,1380,1213],{"class":83},[63,1382,1216],{"class":92},[63,1384,1219],{"class":83},[63,1386,1222],{"class":76},[63,1388,1389],{"class":83},");   ",[63,1391,1392],{"class":69},"-- can SET these values\n",[63,1394,1396],{"class":65,"line":1395},30,[63,1397,1398],{"class":69},"  -- USING: which rows are visible (the user can only update rows they can see)\n",[63,1400,1402],{"class":65,"line":1401},31,[63,1403,1404],{"class":69},"  -- WITH CHECK: what the new values can be (can't reassign to another user)\n",[63,1406,1408],{"class":65,"line":1407},32,[63,1409,103],{"emptyLinePlaceholder":102},[63,1411,1413],{"class":65,"line":1412},33,[63,1414,1415],{"class":69},"-- A DELETE policy: users can delete only their own orders\n",[63,1417,1419,1421,1423,1426,1428],{"class":65,"line":1418},34,[63,1420,77],{"class":76},[63,1422,1172],{"class":76},[63,1424,1425],{"class":83}," delete_own_orders ",[63,1427,744],{"class":76},[63,1429,1180],{"class":83},[63,1431,1433,1435],{"class":65,"line":1432},35,[63,1434,1185],{"class":76},[63,1436,1437],{"class":76}," DELETE\n",[63,1439,1441,1443],{"class":65,"line":1440},36,[63,1442,1193],{"class":76},[63,1444,1276],{"class":83},[63,1446,1448,1450,1452,1454,1456,1458,1460,1462],{"class":65,"line":1447},37,[63,1449,1204],{"class":76},[63,1451,1207],{"class":83},[63,1453,1210],{"class":76},[63,1455,1213],{"class":83},[63,1457,1216],{"class":92},[63,1459,1219],{"class":83},[63,1461,1222],{"class":76},[63,1463,1225],{"class":83},[63,1465,1467],{"class":65,"line":1466},38,[63,1468,1469],{"class":69},"  -- DELETE uses USING (which rows are visible for deletion). No WITH CHECK.\n",[203,1471,1473],{"id":1472},"using-vs-with-check-the-two-predicates","USING vs WITH CHECK — the two predicates",[345,1475,1476,1495],{},[348,1477,1478],{},[351,1479,1480,1483,1489],{},[354,1481,1482],{},"Command",[354,1484,1485,1488],{},[23,1486,1487],{},"USING"," (visibility)",[354,1490,1491,1494],{},[23,1492,1493],{},"WITH CHECK"," (validation)",[364,1496,1497,1509,1521,1532],{},[351,1498,1499,1503,1506],{},[369,1500,1501],{},[23,1502,373],{},[369,1504,1505],{},"✓ (filters visible rows)",[369,1507,1508],{},"—",[351,1510,1511,1515,1518],{},[369,1512,1513],{},[23,1514,399],{},[369,1516,1517],{},"✓ (can only update visible rows)",[369,1519,1520],{},"✓ (new row must pass)",[351,1522,1523,1527,1530],{},[369,1524,1525],{},[23,1526,411],{},[369,1528,1529],{},"✓ (can only delete visible rows)",[369,1531,1508],{},[351,1533,1534,1538,1540],{},[369,1535,1536],{},[23,1537,386],{},[369,1539,1508],{},[369,1541,1520],{},[14,1543,1544,1545,1547,1548,1550,1551,1553,1554,1556,1557,1560],{},"For ",[23,1546,399],{},", you need BOTH: ",[23,1549,1487],{}," (can see this row) and ",[23,1552,1493],{}," (can change it to this value). Without ",[23,1555,1493],{},", a user could update their row's ",[23,1558,1559],{},"user_id"," to someone else's — a privilege escalation.",[203,1562,1564],{"id":1563},"policy-combination-permissive-or-vs-restrictive-and","Policy combination — permissive (OR) vs restrictive (AND)",[51,1566,1567],{"language":53},[55,1568,1570],{"className":57,"code":1569,"language":53,"meta":59,"style":59},"-- Multiple permissive policies (default) combine with OR:\n-- a row visible to ANY permissive policy is visible.\nCREATE POLICY p1 ON orders FOR SELECT USING (status = 'active');\nCREATE POLICY p2 ON orders FOR SELECT USING (user_id = 42);\n-- Visible rows: status='active' OR user_id=42\n\n-- AS RESTRICTIVE policies combine with AND:\n-- a row must pass ALL restrictive policies (in addition to the permissive OR).\nCREATE POLICY restrict_active_tenant ON orders\n  FOR SELECT\n  AS RESTRICTIVE\n  USING (tenant_id = current_setting('app.tenant')::bigint);\n-- Visible rows: (status='active' OR user_id=42) AND tenant_id=current_tenant\n-- Use RESTRICTIVE for guard-rail policies (tenant isolation, soft-delete filter)\n-- that should AND with everything else.\n",[23,1571,1572,1577,1582,1616,1644,1649,1653,1658,1663,1676,1682,1690,1710,1715,1720],{"__ignoreMap":59},[63,1573,1574],{"class":65,"line":66},[63,1575,1576],{"class":69},"-- Multiple permissive policies (default) combine with OR:\n",[63,1578,1579],{"class":65,"line":73},[63,1580,1581],{"class":69},"-- a row visible to ANY permissive policy is visible.\n",[63,1583,1584,1586,1588,1591,1593,1595,1597,1599,1602,1605,1608,1611,1614],{"class":65,"line":99},[63,1585,77],{"class":76},[63,1587,1172],{"class":76},[63,1589,1590],{"class":83}," p1 ",[63,1592,744],{"class":76},[63,1594,569],{"class":83},[63,1596,943],{"class":76},[63,1598,164],{"class":76},[63,1600,1601],{"class":76}," USING",[63,1603,1604],{"class":83}," (",[63,1606,1607],{"class":76},"status",[63,1609,1610],{"class":76}," =",[63,1612,1613],{"class":92}," 'active'",[63,1615,1225],{"class":83},[63,1617,1618,1620,1622,1625,1627,1629,1631,1633,1635,1637,1639,1642],{"class":65,"line":106},[63,1619,77],{"class":76},[63,1621,1172],{"class":76},[63,1623,1624],{"class":83}," p2 ",[63,1626,744],{"class":76},[63,1628,569],{"class":83},[63,1630,943],{"class":76},[63,1632,164],{"class":76},[63,1634,1601],{"class":76},[63,1636,1207],{"class":83},[63,1638,1210],{"class":76},[63,1640,1641],{"class":294}," 42",[63,1643,1225],{"class":83},[63,1645,1646],{"class":65,"line":112},[63,1647,1648],{"class":69},"-- Visible rows: status='active' OR user_id=42\n",[63,1650,1651],{"class":65,"line":122},[63,1652,103],{"emptyLinePlaceholder":102},[63,1654,1655],{"class":65,"line":127},[63,1656,1657],{"class":69},"-- AS RESTRICTIVE policies combine with AND:\n",[63,1659,1660],{"class":65,"line":133},[63,1661,1662],{"class":69},"-- a row must pass ALL restrictive policies (in addition to the permissive OR).\n",[63,1664,1665,1667,1669,1672,1674],{"class":65,"line":148},[63,1666,77],{"class":76},[63,1668,1172],{"class":76},[63,1670,1671],{"class":83}," restrict_active_tenant ",[63,1673,744],{"class":76},[63,1675,1180],{"class":83},[63,1677,1678,1680],{"class":65,"line":153},[63,1679,1185],{"class":76},[63,1681,1188],{"class":76},[63,1683,1684,1687],{"class":65,"line":159},[63,1685,1686],{"class":76},"  AS",[63,1688,1689],{"class":83}," RESTRICTIVE\n",[63,1691,1692,1694,1697,1699,1701,1704,1706,1708],{"class":65,"line":186},[63,1693,1204],{"class":76},[63,1695,1696],{"class":83}," (tenant_id ",[63,1698,1210],{"class":76},[63,1700,1213],{"class":83},[63,1702,1703],{"class":92},"'app.tenant'",[63,1705,1219],{"class":83},[63,1707,1222],{"class":76},[63,1709,1225],{"class":83},[63,1711,1712],{"class":65,"line":192},[63,1713,1714],{"class":69},"-- Visible rows: (status='active' OR user_id=42) AND tenant_id=current_tenant\n",[63,1716,1717],{"class":65,"line":198},[63,1718,1719],{"class":69},"-- Use RESTRICTIVE for guard-rail policies (tenant isolation, soft-delete filter)\n",[63,1721,1722],{"class":65,"line":689},[63,1723,1724],{"class":69},"-- that should AND with everything else.\n",[203,1726,1728],{"id":1727},"table-owner-and-superuser-bypass","Table owner and superuser bypass",[51,1730,1731],{"language":53},[55,1732,1734],{"className":57,"code":1733,"language":53,"meta":59,"style":59},"-- By DEFAULT, the table OWNER bypasses RLS policies.\n-- Superusers ALWAYS bypass RLS (can't be changed).\n-- To enforce RLS on the owner too:\nALTER TABLE orders FORCE ROW LEVEL SECURITY;\n-- Now the owner is subject to policies. Superusers still bypass.\n\n-- BYPASSRLS attribute: a role with BYPASSRLS ignores all RLS policies\nCREATE ROLE admin_role LOGIN BYPASSRLS;\n-- Don't grant BYPASSRLS to app roles — it defeats the purpose of RLS.\n-- Reserve for migration\u002Fadmin roles that need to see all rows.\n",[23,1735,1736,1741,1746,1751,1770,1775,1779,1784,1798,1803],{"__ignoreMap":59},[63,1737,1738],{"class":65,"line":66},[63,1739,1740],{"class":69},"-- By DEFAULT, the table OWNER bypasses RLS policies.\n",[63,1742,1743],{"class":65,"line":73},[63,1744,1745],{"class":69},"-- Superusers ALWAYS bypass RLS (can't be changed).\n",[63,1747,1748],{"class":65,"line":99},[63,1749,1750],{"class":69},"-- To enforce RLS on the owner too:\n",[63,1752,1753,1755,1757,1759,1762,1764,1766,1768],{"class":65,"line":106},[63,1754,281],{"class":76},[63,1756,1125],{"class":76},[63,1758,569],{"class":83},[63,1760,1761],{"class":76},"FORCE",[63,1763,1133],{"class":76},[63,1765,1136],{"class":76},[63,1767,1139],{"class":76},[63,1769,96],{"class":83},[63,1771,1772],{"class":65,"line":112},[63,1773,1774],{"class":69},"-- Now the owner is subject to policies. Superusers still bypass.\n",[63,1776,1777],{"class":65,"line":122},[63,1778,103],{"emptyLinePlaceholder":102},[63,1780,1781],{"class":65,"line":127},[63,1782,1783],{"class":69},"-- BYPASSRLS attribute: a role with BYPASSRLS ignores all RLS policies\n",[63,1785,1786,1788,1790,1793,1795],{"class":65,"line":133},[63,1787,77],{"class":76},[63,1789,80],{"class":76},[63,1791,1792],{"class":83}," admin_role ",[63,1794,45],{"class":76},[63,1796,1797],{"class":83}," BYPASSRLS;\n",[63,1799,1800],{"class":65,"line":148},[63,1801,1802],{"class":69},"-- Don't grant BYPASSRLS to app roles — it defeats the purpose of RLS.\n",[63,1804,1805],{"class":65,"line":153},[63,1806,1807],{"class":69},"-- Reserve for migration\u002Fadmin roles that need to see all rows.\n",[32,1809,1811],{"id":1810},"complex-implementation-multi-tenant-saas-security-model","Complex Implementation — Multi-Tenant SaaS Security Model",[14,1813,1814],{},"A complete multi-tenant security model: group roles for team management, default privileges for future-proofing, RLS policies for tenant isolation via session variables, a read-only analytics role, and a service role with limited access.",[51,1816,1817],{"language":53},[55,1818,1820],{"className":57,"code":1819,"language":53,"meta":59,"style":59},"-- ── 1. Group roles for team-based access ────────────────────────\nCREATE ROLE tenant_app_role;        -- app connections (read\u002Fwrite tenant data)\nCREATE ROLE tenant_readonly;        -- analytics (read-only)\nCREATE ROLE tenant_migrator;        -- schema migrations (DDL, no BYPASSRLS)\n\n-- ── 2. The app role (non-owner, non-superuser, no BYPASSRLS) ────\n-- CRITICAL: the app role must NOT own the tables (owners bypass RLS)\n-- and must NOT be a superuser or have BYPASSRLS.\nCREATE ROLE app_connection LOGIN PASSWORD '...' NOSUPERUSER NOBYPASSRLS;\nGRANT tenant_app_role TO app_connection;\n-- app_connection inherits tenant_app_role's privileges.\n\n-- ── 3. Schema and tenant-scoped tables ──────────────────────────\nCREATE SCHEMA IF NOT EXISTS tenant_data;\n\nCREATE TABLE tenant_data.orders (\n  id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,\n  tenant_id BIGINT NOT NULL,                -- the tenant scope column\n  customer_id BIGINT NOT NULL,\n  amount NUMERIC NOT NULL,\n  created_at TIMESTAMPTZ NOT NULL DEFAULT now()\n);\n\nCREATE TABLE tenant_data.customers (\n  id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,\n  tenant_id BIGINT NOT NULL,\n  name TEXT NOT NULL,\n  email TEXT\n);\n\n-- Index the tenant_id column (RLS policies filter on it → needs an index)\nCREATE INDEX orders_tenant_idx ON tenant_data.orders(tenant_id);\nCREATE INDEX customers_tenant_idx ON tenant_data.customers(tenant_id);\n\n-- ── 4. Enable RLS on all tenant-scoped tables ───────────────────\nALTER TABLE tenant_data.orders ENABLE ROW LEVEL SECURITY;\nALTER TABLE tenant_data.customers ENABLE ROW LEVEL SECURITY;\n-- Force RLS on the owner too (in case the migrator role owns the tables):\nALTER TABLE tenant_data.orders FORCE ROW LEVEL SECURITY;\nALTER TABLE tenant_data.customers FORCE ROW LEVEL SECURITY;\n\n-- ── 5. RLS policy: tenant isolation via session variable ────────\n-- The app sets app.current_tenant at the start of each request.\n-- RLS ensures no query can leak data across tenants.\nCREATE POLICY tenant_isolation ON tenant_data.orders\n  FOR ALL\n  TO tenant_app_role\n  USING (tenant_id = current_setting('app.current_tenant', true)::bigint)\n  WITH CHECK (tenant_id = current_setting('app.current_tenant', true)::bigint);\n-- current_setting('app.current_tenant', true) returns NULL if unset\n-- (the `true` arg suppresses the error). NULL::bigint → NULL → no rows match\n-- → deny-by-default when the tenant isn't set. Safe.\n\nCREATE POLICY tenant_isolation_customers ON tenant_data.customers\n  FOR ALL\n  TO tenant_app_role\n  USING (tenant_id = current_setting('app.current_tenant', true)::bigint)\n  WITH CHECK (tenant_id = current_setting('app.current_tenant', true)::bigint);\n\n-- ── 6. Table-level grants ───────────────────────────────────────\nGRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA tenant_data TO tenant_app_role;\nGRANT SELECT ON ALL TABLES IN SCHEMA tenant_data TO tenant_readonly;\nGRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA tenant_data TO tenant_app_role;\n\n-- ── 7. DEFAULT PRIVILEGES for future tables ─────────────────────\n-- The migrator role creates future tables. Set defaults so the app role\n-- automatically gets access to new tables.\nALTER DEFAULT PRIVILEGES FOR ROLE tenant_migrator IN SCHEMA tenant_data\n  GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO tenant_app_role;\nALTER DEFAULT PRIVILEGES FOR ROLE tenant_migrator IN SCHEMA tenant_data\n  GRANT SELECT ON TABLES TO tenant_readonly;\nALTER DEFAULT PRIVILEGES FOR ROLE tenant_migrator IN SCHEMA tenant_data\n  GRANT USAGE, SELECT ON SEQUENCES TO tenant_app_role;\n\n-- ── 8. Usage: the app sets the tenant per request ───────────────\n-- App code (after authenticating the user, determining their tenant):\n--   SET app.current_tenant = '42';\n--   SELECT * FROM tenant_data.orders;  -- only sees orders where tenant_id=42\n--   INSERT INTO tenant_data.orders (tenant_id, ...) VALUES (42, ...);  -- OK\n--   INSERT INTO tenant_data.orders (tenant_id, ...) VALUES (99, ...);  -- ERROR (WITH CHECK fails)\n-- Even if the app has a bug (e.g., missing WHERE tenant_id=?), RLS prevents\n-- cross-tenant data access. The database enforces it, not the application.\n",[23,1821,1822,1827,1839,1851,1863,1867,1872,1877,1882,1900,1912,1917,1921,1926,1945,1949,1961,1987,2003,2014,2026,2044,2048,2052,2063,2081,2091,2103,2111,2115,2119,2124,2147,2167,2171,2176,2199,2221,2226,2250,2273,2278,2284,2290,2296,2315,2323,2331,2353,2374,2380,2386,2392,2397,2416,2423,2430,2449,2470,2475,2481,2516,2538,2561,2566,2572,2578,2584,2607,2634,2655,2670,2691,2708,2713,2719,2725,2731,2737,2743,2749,2755],{"__ignoreMap":59},[63,1823,1824],{"class":65,"line":66},[63,1825,1826],{"class":69},"-- ── 1. Group roles for team-based access ────────────────────────\n",[63,1828,1829,1831,1833,1836],{"class":65,"line":73},[63,1830,77],{"class":76},[63,1832,80],{"class":76},[63,1834,1835],{"class":83}," tenant_app_role;        ",[63,1837,1838],{"class":69},"-- app connections (read\u002Fwrite tenant data)\n",[63,1840,1841,1843,1845,1848],{"class":65,"line":99},[63,1842,77],{"class":76},[63,1844,80],{"class":76},[63,1846,1847],{"class":83}," tenant_readonly;        ",[63,1849,1850],{"class":69},"-- analytics (read-only)\n",[63,1852,1853,1855,1857,1860],{"class":65,"line":106},[63,1854,77],{"class":76},[63,1856,80],{"class":76},[63,1858,1859],{"class":83}," tenant_migrator;        ",[63,1861,1862],{"class":69},"-- schema migrations (DDL, no BYPASSRLS)\n",[63,1864,1865],{"class":65,"line":112},[63,1866,103],{"emptyLinePlaceholder":102},[63,1868,1869],{"class":65,"line":122},[63,1870,1871],{"class":69},"-- ── 2. The app role (non-owner, non-superuser, no BYPASSRLS) ────\n",[63,1873,1874],{"class":65,"line":127},[63,1875,1876],{"class":69},"-- CRITICAL: the app role must NOT own the tables (owners bypass RLS)\n",[63,1878,1879],{"class":65,"line":133},[63,1880,1881],{"class":69},"-- and must NOT be a superuser or have BYPASSRLS.\n",[63,1883,1884,1886,1888,1891,1893,1895,1897],{"class":65,"line":148},[63,1885,77],{"class":76},[63,1887,80],{"class":76},[63,1889,1890],{"class":83}," app_connection ",[63,1892,45],{"class":76},[63,1894,89],{"class":76},[63,1896,229],{"class":92},[63,1898,1899],{"class":83}," NOSUPERUSER NOBYPASSRLS;\n",[63,1901,1902,1904,1907,1909],{"class":65,"line":153},[63,1903,136],{"class":76},[63,1905,1906],{"class":83}," tenant_app_role ",[63,1908,142],{"class":76},[63,1910,1911],{"class":83}," app_connection;\n",[63,1913,1914],{"class":65,"line":159},[63,1915,1916],{"class":69},"-- app_connection inherits tenant_app_role's privileges.\n",[63,1918,1919],{"class":65,"line":186},[63,1920,103],{"emptyLinePlaceholder":102},[63,1922,1923],{"class":65,"line":192},[63,1924,1925],{"class":69},"-- ── 3. Schema and tenant-scoped tables ──────────────────────────\n",[63,1927,1928,1930,1932,1936,1939,1942],{"class":65,"line":198},[63,1929,77],{"class":76},[63,1931,176],{"class":76},[63,1933,1935],{"class":1934},"sIsaT"," IF",[63,1937,1938],{"class":76}," NOT",[63,1940,1941],{"class":76}," EXISTS",[63,1943,1944],{"class":83}," tenant_data;\n",[63,1946,1947],{"class":65,"line":689},[63,1948,103],{"emptyLinePlaceholder":102},[63,1950,1951,1953,1955,1958],{"class":65,"line":695},[63,1952,77],{"class":76},[63,1954,1125],{"class":76},[63,1956,1957],{"class":1934}," tenant_data",[63,1959,1960],{"class":83},".orders (\n",[63,1962,1963,1966,1969,1972,1975,1978,1981,1984],{"class":65,"line":701},[63,1964,1965],{"class":83},"  id ",[63,1967,1968],{"class":76},"BIGINT",[63,1970,1971],{"class":76}," GENERATED",[63,1973,1974],{"class":76}," ALWAYS",[63,1976,1977],{"class":76}," AS",[63,1979,1980],{"class":76}," IDENTITY",[63,1982,1983],{"class":76}," PRIMARY KEY",[63,1985,1986],{"class":83},",\n",[63,1988,1989,1992,1994,1997,2000],{"class":65,"line":707},[63,1990,1991],{"class":83},"  tenant_id ",[63,1993,1968],{"class":76},[63,1995,1996],{"class":76}," NOT NULL",[63,1998,1999],{"class":83},",                ",[63,2001,2002],{"class":69},"-- the tenant scope column\n",[63,2004,2005,2008,2010,2012],{"class":65,"line":712},[63,2006,2007],{"class":83},"  customer_id ",[63,2009,1968],{"class":76},[63,2011,1996],{"class":76},[63,2013,1986],{"class":83},[63,2015,2016,2019,2022,2024],{"class":65,"line":718},[63,2017,2018],{"class":83},"  amount ",[63,2020,2021],{"class":76},"NUMERIC",[63,2023,1996],{"class":76},[63,2025,1986],{"class":83},[63,2027,2028,2031,2034,2036,2038,2041],{"class":65,"line":736},[63,2029,2030],{"class":83},"  created_at ",[63,2032,2033],{"class":76},"TIMESTAMPTZ",[63,2035,1996],{"class":76},[63,2037,825],{"class":76},[63,2039,2040],{"class":76}," now",[63,2042,2043],{"class":83},"()\n",[63,2045,2046],{"class":65,"line":757},[63,2047,1225],{"class":83},[63,2049,2050],{"class":65,"line":970},[63,2051,103],{"emptyLinePlaceholder":102},[63,2053,2054,2056,2058,2060],{"class":65,"line":992},[63,2055,77],{"class":76},[63,2057,1125],{"class":76},[63,2059,1957],{"class":1934},[63,2061,2062],{"class":83},".customers (\n",[63,2064,2065,2067,2069,2071,2073,2075,2077,2079],{"class":65,"line":1007},[63,2066,1965],{"class":83},[63,2068,1968],{"class":76},[63,2070,1971],{"class":76},[63,2072,1974],{"class":76},[63,2074,1977],{"class":76},[63,2076,1980],{"class":76},[63,2078,1983],{"class":76},[63,2080,1986],{"class":83},[63,2082,2083,2085,2087,2089],{"class":65,"line":1013},[63,2084,1991],{"class":83},[63,2086,1968],{"class":76},[63,2088,1996],{"class":76},[63,2090,1986],{"class":83},[63,2092,2093,2096,2099,2101],{"class":65,"line":1340},[63,2094,2095],{"class":76},"  name",[63,2097,2098],{"class":76}," TEXT",[63,2100,1996],{"class":76},[63,2102,1986],{"class":83},[63,2104,2105,2108],{"class":65,"line":1347},[63,2106,2107],{"class":83},"  email ",[63,2109,2110],{"class":76},"TEXT\n",[63,2112,2113],{"class":65,"line":1370},[63,2114,1225],{"class":83},[63,2116,2117],{"class":65,"line":1395},[63,2118,103],{"emptyLinePlaceholder":102},[63,2120,2121],{"class":65,"line":1401},[63,2122,2123],{"class":69},"-- Index the tenant_id column (RLS policies filter on it → needs an index)\n",[63,2125,2126,2128,2131,2134,2136,2138,2141,2144],{"class":65,"line":1407},[63,2127,77],{"class":76},[63,2129,2130],{"class":76}," INDEX",[63,2132,2133],{"class":1934}," orders_tenant_idx",[63,2135,167],{"class":76},[63,2137,1957],{"class":294},[63,2139,2140],{"class":83},".",[63,2142,2143],{"class":294},"orders",[63,2145,2146],{"class":83},"(tenant_id);\n",[63,2148,2149,2151,2153,2156,2158,2160,2162,2165],{"class":65,"line":1412},[63,2150,77],{"class":76},[63,2152,2130],{"class":76},[63,2154,2155],{"class":1934}," customers_tenant_idx",[63,2157,167],{"class":76},[63,2159,1957],{"class":294},[63,2161,2140],{"class":83},[63,2163,2164],{"class":294},"customers",[63,2166,2146],{"class":83},[63,2168,2169],{"class":65,"line":1418},[63,2170,103],{"emptyLinePlaceholder":102},[63,2172,2173],{"class":65,"line":1432},[63,2174,2175],{"class":69},"-- ── 4. Enable RLS on all tenant-scoped tables ───────────────────\n",[63,2177,2178,2180,2182,2184,2186,2188,2191,2193,2195,2197],{"class":65,"line":1440},[63,2179,281],{"class":76},[63,2181,1125],{"class":76},[63,2183,1957],{"class":294},[63,2185,2140],{"class":83},[63,2187,2143],{"class":294},[63,2189,2190],{"class":76}," ENABLE",[63,2192,1133],{"class":76},[63,2194,1136],{"class":76},[63,2196,1139],{"class":76},[63,2198,96],{"class":83},[63,2200,2201,2203,2205,2207,2209,2211,2213,2215,2217,2219],{"class":65,"line":1447},[63,2202,281],{"class":76},[63,2204,1125],{"class":76},[63,2206,1957],{"class":294},[63,2208,2140],{"class":83},[63,2210,2164],{"class":294},[63,2212,2190],{"class":76},[63,2214,1133],{"class":76},[63,2216,1136],{"class":76},[63,2218,1139],{"class":76},[63,2220,96],{"class":83},[63,2222,2223],{"class":65,"line":1466},[63,2224,2225],{"class":69},"-- Force RLS on the owner too (in case the migrator role owns the tables):\n",[63,2227,2229,2231,2233,2235,2237,2239,2242,2244,2246,2248],{"class":65,"line":2228},39,[63,2230,281],{"class":76},[63,2232,1125],{"class":76},[63,2234,1957],{"class":294},[63,2236,2140],{"class":83},[63,2238,2143],{"class":294},[63,2240,2241],{"class":76}," FORCE",[63,2243,1133],{"class":76},[63,2245,1136],{"class":76},[63,2247,1139],{"class":76},[63,2249,96],{"class":83},[63,2251,2253,2255,2257,2259,2261,2263,2265,2267,2269,2271],{"class":65,"line":2252},40,[63,2254,281],{"class":76},[63,2256,1125],{"class":76},[63,2258,1957],{"class":294},[63,2260,2140],{"class":83},[63,2262,2164],{"class":294},[63,2264,2241],{"class":76},[63,2266,1133],{"class":76},[63,2268,1136],{"class":76},[63,2270,1139],{"class":76},[63,2272,96],{"class":83},[63,2274,2276],{"class":65,"line":2275},41,[63,2277,103],{"emptyLinePlaceholder":102},[63,2279,2281],{"class":65,"line":2280},42,[63,2282,2283],{"class":69},"-- ── 5. RLS policy: tenant isolation via session variable ────────\n",[63,2285,2287],{"class":65,"line":2286},43,[63,2288,2289],{"class":69},"-- The app sets app.current_tenant at the start of each request.\n",[63,2291,2293],{"class":65,"line":2292},44,[63,2294,2295],{"class":69},"-- RLS ensures no query can leak data across tenants.\n",[63,2297,2299,2301,2303,2306,2308,2310,2312],{"class":65,"line":2298},45,[63,2300,77],{"class":76},[63,2302,1172],{"class":76},[63,2304,2305],{"class":83}," tenant_isolation ",[63,2307,744],{"class":76},[63,2309,1957],{"class":294},[63,2311,2140],{"class":83},[63,2313,2314],{"class":294},"orders\n",[63,2316,2318,2320],{"class":65,"line":2317},46,[63,2319,1185],{"class":76},[63,2321,2322],{"class":83}," ALL\n",[63,2324,2326,2328],{"class":65,"line":2325},47,[63,2327,1193],{"class":76},[63,2329,2330],{"class":83}," tenant_app_role\n",[63,2332,2334,2336,2338,2340,2342,2345,2348,2350],{"class":65,"line":2333},48,[63,2335,1204],{"class":76},[63,2337,1696],{"class":83},[63,2339,1210],{"class":76},[63,2341,1213],{"class":83},[63,2343,2344],{"class":92},"'app.current_tenant'",[63,2346,2347],{"class":83},", true)::",[63,2349,1222],{"class":76},[63,2351,2352],{"class":83},")\n",[63,2354,2356,2358,2360,2362,2364,2366,2368,2370,2372],{"class":65,"line":2355},49,[63,2357,1281],{"class":76},[63,2359,1284],{"class":76},[63,2361,1696],{"class":83},[63,2363,1210],{"class":76},[63,2365,1213],{"class":83},[63,2367,2344],{"class":92},[63,2369,2347],{"class":83},[63,2371,1222],{"class":76},[63,2373,1225],{"class":83},[63,2375,2377],{"class":65,"line":2376},50,[63,2378,2379],{"class":69},"-- current_setting('app.current_tenant', true) returns NULL if unset\n",[63,2381,2383],{"class":65,"line":2382},51,[63,2384,2385],{"class":69},"-- (the `true` arg suppresses the error). NULL::bigint → NULL → no rows match\n",[63,2387,2389],{"class":65,"line":2388},52,[63,2390,2391],{"class":69},"-- → deny-by-default when the tenant isn't set. Safe.\n",[63,2393,2395],{"class":65,"line":2394},53,[63,2396,103],{"emptyLinePlaceholder":102},[63,2398,2400,2402,2404,2407,2409,2411,2413],{"class":65,"line":2399},54,[63,2401,77],{"class":76},[63,2403,1172],{"class":76},[63,2405,2406],{"class":83}," tenant_isolation_customers ",[63,2408,744],{"class":76},[63,2410,1957],{"class":294},[63,2412,2140],{"class":83},[63,2414,2415],{"class":294},"customers\n",[63,2417,2419,2421],{"class":65,"line":2418},55,[63,2420,1185],{"class":76},[63,2422,2322],{"class":83},[63,2424,2426,2428],{"class":65,"line":2425},56,[63,2427,1193],{"class":76},[63,2429,2330],{"class":83},[63,2431,2433,2435,2437,2439,2441,2443,2445,2447],{"class":65,"line":2432},57,[63,2434,1204],{"class":76},[63,2436,1696],{"class":83},[63,2438,1210],{"class":76},[63,2440,1213],{"class":83},[63,2442,2344],{"class":92},[63,2444,2347],{"class":83},[63,2446,1222],{"class":76},[63,2448,2352],{"class":83},[63,2450,2452,2454,2456,2458,2460,2462,2464,2466,2468],{"class":65,"line":2451},58,[63,2453,1281],{"class":76},[63,2455,1284],{"class":76},[63,2457,1696],{"class":83},[63,2459,1210],{"class":76},[63,2461,1213],{"class":83},[63,2463,2344],{"class":92},[63,2465,2347],{"class":83},[63,2467,1222],{"class":76},[63,2469,1225],{"class":83},[63,2471,2473],{"class":65,"line":2472},59,[63,2474,103],{"emptyLinePlaceholder":102},[63,2476,2478],{"class":65,"line":2477},60,[63,2479,2480],{"class":69},"-- ── 6. Table-level grants ───────────────────────────────────────\n",[63,2482,2484,2486,2488,2490,2492,2494,2496,2498,2500,2502,2504,2506,2508,2511,2513],{"class":65,"line":2483},61,[63,2485,136],{"class":76},[63,2487,164],{"class":76},[63,2489,558],{"class":83},[63,2491,386],{"class":76},[63,2493,558],{"class":83},[63,2495,399],{"class":76},[63,2497,558],{"class":83},[63,2499,411],{"class":76},[63,2501,167],{"class":76},[63,2503,170],{"class":83},[63,2505,173],{"class":76},[63,2507,176],{"class":76},[63,2509,2510],{"class":83}," tenant_data ",[63,2512,142],{"class":76},[63,2514,2515],{"class":83}," tenant_app_role;\n",[63,2517,2519,2521,2523,2525,2527,2529,2531,2533,2535],{"class":65,"line":2518},62,[63,2520,136],{"class":76},[63,2522,164],{"class":76},[63,2524,167],{"class":76},[63,2526,170],{"class":83},[63,2528,173],{"class":76},[63,2530,176],{"class":76},[63,2532,2510],{"class":83},[63,2534,142],{"class":76},[63,2536,2537],{"class":83}," tenant_readonly;\n",[63,2539,2541,2543,2545,2547,2549,2551,2553,2555,2557,2559],{"class":65,"line":2540},63,[63,2542,136],{"class":76},[63,2544,669],{"class":83},[63,2546,373],{"class":76},[63,2548,167],{"class":76},[63,2550,676],{"class":83},[63,2552,173],{"class":76},[63,2554,176],{"class":76},[63,2556,2510],{"class":83},[63,2558,142],{"class":76},[63,2560,2515],{"class":83},[63,2562,2564],{"class":65,"line":2563},64,[63,2565,103],{"emptyLinePlaceholder":102},[63,2567,2569],{"class":65,"line":2568},65,[63,2570,2571],{"class":69},"-- ── 7. DEFAULT PRIVILEGES for future tables ─────────────────────\n",[63,2573,2575],{"class":65,"line":2574},66,[63,2576,2577],{"class":69},"-- The migrator role creates future tables. Set defaults so the app role\n",[63,2579,2581],{"class":65,"line":2580},67,[63,2582,2583],{"class":69},"-- automatically gets access to new tables.\n",[63,2585,2587,2589,2591,2593,2595,2597,2600,2602,2604],{"class":65,"line":2586},68,[63,2588,281],{"class":76},[63,2590,825],{"class":76},[63,2592,828],{"class":83},[63,2594,943],{"class":76},[63,2596,80],{"class":76},[63,2598,2599],{"class":83}," tenant_migrator ",[63,2601,173],{"class":76},[63,2603,176],{"class":76},[63,2605,2606],{"class":83}," tenant_data\n",[63,2608,2610,2612,2614,2616,2618,2620,2622,2624,2626,2628,2630,2632],{"class":65,"line":2609},69,[63,2611,840],{"class":76},[63,2613,164],{"class":76},[63,2615,558],{"class":83},[63,2617,386],{"class":76},[63,2619,558],{"class":83},[63,2621,399],{"class":76},[63,2623,558],{"class":83},[63,2625,411],{"class":76},[63,2627,167],{"class":76},[63,2629,855],{"class":83},[63,2631,142],{"class":76},[63,2633,2515],{"class":83},[63,2635,2637,2639,2641,2643,2645,2647,2649,2651,2653],{"class":65,"line":2636},70,[63,2638,281],{"class":76},[63,2640,825],{"class":76},[63,2642,828],{"class":83},[63,2644,943],{"class":76},[63,2646,80],{"class":76},[63,2648,2599],{"class":83},[63,2650,173],{"class":76},[63,2652,176],{"class":76},[63,2654,2606],{"class":83},[63,2656,2658,2660,2662,2664,2666,2668],{"class":65,"line":2657},71,[63,2659,840],{"class":76},[63,2661,164],{"class":76},[63,2663,167],{"class":76},[63,2665,855],{"class":83},[63,2667,142],{"class":76},[63,2669,2537],{"class":83},[63,2671,2673,2675,2677,2679,2681,2683,2685,2687,2689],{"class":65,"line":2672},72,[63,2674,281],{"class":76},[63,2676,825],{"class":76},[63,2678,828],{"class":83},[63,2680,943],{"class":76},[63,2682,80],{"class":76},[63,2684,2599],{"class":83},[63,2686,173],{"class":76},[63,2688,176],{"class":76},[63,2690,2606],{"class":83},[63,2692,2694,2696,2698,2700,2702,2704,2706],{"class":65,"line":2693},73,[63,2695,840],{"class":76},[63,2697,669],{"class":83},[63,2699,373],{"class":76},[63,2701,167],{"class":76},[63,2703,890],{"class":83},[63,2705,142],{"class":76},[63,2707,2515],{"class":83},[63,2709,2711],{"class":65,"line":2710},74,[63,2712,103],{"emptyLinePlaceholder":102},[63,2714,2716],{"class":65,"line":2715},75,[63,2717,2718],{"class":69},"-- ── 8. Usage: the app sets the tenant per request ───────────────\n",[63,2720,2722],{"class":65,"line":2721},76,[63,2723,2724],{"class":69},"-- App code (after authenticating the user, determining their tenant):\n",[63,2726,2728],{"class":65,"line":2727},77,[63,2729,2730],{"class":69},"--   SET app.current_tenant = '42';\n",[63,2732,2734],{"class":65,"line":2733},78,[63,2735,2736],{"class":69},"--   SELECT * FROM tenant_data.orders;  -- only sees orders where tenant_id=42\n",[63,2738,2740],{"class":65,"line":2739},79,[63,2741,2742],{"class":69},"--   INSERT INTO tenant_data.orders (tenant_id, ...) VALUES (42, ...);  -- OK\n",[63,2744,2746],{"class":65,"line":2745},80,[63,2747,2748],{"class":69},"--   INSERT INTO tenant_data.orders (tenant_id, ...) VALUES (99, ...);  -- ERROR (WITH CHECK fails)\n",[63,2750,2752],{"class":65,"line":2751},81,[63,2753,2754],{"class":69},"-- Even if the app has a bug (e.g., missing WHERE tenant_id=?), RLS prevents\n",[63,2756,2758],{"class":65,"line":2757},82,[63,2759,2760],{"class":69},"-- cross-tenant data access. The database enforces it, not the application.\n",[32,2762,2764],{"id":2763},"anti-pattern-grant-all-privileges-to-every-role","Anti-Pattern: GRANT ALL PRIVILEGES to Every Role",[51,2766,2767],{"language":53},[55,2768,2770],{"className":57,"code":2769,"language":53,"meta":59,"style":59},"-- ❌ WRONG: granting everything to everyone\nGRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO PUBLIC;\n-- ALL PRIVILEGES includes TRUNCATE, REFERENCES, TRIGGER — none of which\n-- the app needs. PUBLIC means EVERY role. This is how data gets deleted\n-- by a role that should only read.\n\n-- ✅ RIGHT: grant exactly what's needed, to specific roles\nGRANT SELECT, INSERT, UPDATE ON orders TO app_role;  -- no DELETE, no TRUNCATE\nGRANT SELECT ON orders TO analytics_role;             -- read-only\n-- Principle of least privilege: if the app doesn't need DELETE, don't grant it.\n",[23,2771,2772,2777,2799,2804,2809,2814,2818,2823,2849,2867],{"__ignoreMap":59},[63,2773,2774],{"class":65,"line":66},[63,2775,2776],{"class":69},"-- ❌ WRONG: granting everything to everyone\n",[63,2778,2779,2781,2784,2786,2788,2790,2792,2794,2796],{"class":65,"line":73},[63,2780,136],{"class":76},[63,2782,2783],{"class":83}," ALL PRIVILEGES ",[63,2785,744],{"class":76},[63,2787,170],{"class":83},[63,2789,173],{"class":76},[63,2791,176],{"class":76},[63,2793,649],{"class":83},[63,2795,142],{"class":76},[63,2797,2798],{"class":83}," PUBLIC;\n",[63,2800,2801],{"class":65,"line":99},[63,2802,2803],{"class":69},"-- ALL PRIVILEGES includes TRUNCATE, REFERENCES, TRIGGER — none of which\n",[63,2805,2806],{"class":65,"line":106},[63,2807,2808],{"class":69},"-- the app needs. PUBLIC means EVERY role. This is how data gets deleted\n",[63,2810,2811],{"class":65,"line":112},[63,2812,2813],{"class":69},"-- by a role that should only read.\n",[63,2815,2816],{"class":65,"line":122},[63,2817,103],{"emptyLinePlaceholder":102},[63,2819,2820],{"class":65,"line":127},[63,2821,2822],{"class":69},"-- ✅ RIGHT: grant exactly what's needed, to specific roles\n",[63,2824,2825,2827,2829,2831,2833,2835,2837,2839,2841,2843,2846],{"class":65,"line":133},[63,2826,136],{"class":76},[63,2828,164],{"class":76},[63,2830,558],{"class":83},[63,2832,386],{"class":76},[63,2834,558],{"class":83},[63,2836,399],{"class":76},[63,2838,167],{"class":76},[63,2840,569],{"class":83},[63,2842,142],{"class":76},[63,2844,2845],{"class":83}," app_role;  ",[63,2847,2848],{"class":69},"-- no DELETE, no TRUNCATE\n",[63,2850,2851,2853,2855,2857,2859,2861,2864],{"class":65,"line":148},[63,2852,136],{"class":76},[63,2854,164],{"class":76},[63,2856,167],{"class":76},[63,2858,569],{"class":83},[63,2860,142],{"class":76},[63,2862,2863],{"class":83}," analytics_role;             ",[63,2865,2866],{"class":69},"-- read-only\n",[63,2868,2869],{"class":65,"line":153},[63,2870,2871],{"class":69},"-- Principle of least privilege: if the app doesn't need DELETE, don't grant it.\n",[32,2873,2875],{"id":2874},"anti-pattern-superuser-for-application-connections","Anti-Pattern: Superuser for Application Connections",[51,2877,2878],{"language":53},[55,2879,2881],{"className":57,"code":2880,"language":53,"meta":59,"style":59},"-- ❌ WRONG: app connects as superuser\n-- Connection string: postgresql:\u002F\u002Fsuperuser:pass@host\u002Fdb\n-- A single SQL injection → full database compromise.\n-- Superuser bypasses RLS, all permission checks, can DROP databases,\n-- can read pg_shadow (password hashes), can execute OS commands via\n-- COPY TO PROGRAM, can create SECURITY DEFINER functions as any role.\n\n-- ✅ RIGHT: app connects as a dedicated role with minimal privileges\nCREATE ROLE app_role LOGIN PASSWORD '...' NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION NOBYPASSRLS;\nGRANT CONNECT ON DATABASE mydb TO app_role;\nGRANT USAGE ON SCHEMA public TO app_role;\nGRANT SELECT, INSERT, UPDATE ON ALL TABLES IN SCHEMA public TO app_role;\nALTER DEFAULT PRIVILEGES IN SCHEMA public\n  GRANT SELECT, INSERT, UPDATE ON TABLES TO app_role;\n-- If compromised: the attacker can read\u002Finsert\u002Fupdate app tables.\n-- They CANNOT drop the database, read password hashes, bypass RLS,\n-- or escalate to other roles. Blast radius is limited.\n",[23,2882,2883,2888,2893,2898,2903,2908,2913,2917,2922,2940,2959,2976,3004,3018,3040,3045,3050],{"__ignoreMap":59},[63,2884,2885],{"class":65,"line":66},[63,2886,2887],{"class":69},"-- ❌ WRONG: app connects as superuser\n",[63,2889,2890],{"class":65,"line":73},[63,2891,2892],{"class":69},"-- Connection string: postgresql:\u002F\u002Fsuperuser:pass@host\u002Fdb\n",[63,2894,2895],{"class":65,"line":99},[63,2896,2897],{"class":69},"-- A single SQL injection → full database compromise.\n",[63,2899,2900],{"class":65,"line":106},[63,2901,2902],{"class":69},"-- Superuser bypasses RLS, all permission checks, can DROP databases,\n",[63,2904,2905],{"class":65,"line":112},[63,2906,2907],{"class":69},"-- can read pg_shadow (password hashes), can execute OS commands via\n",[63,2909,2910],{"class":65,"line":122},[63,2911,2912],{"class":69},"-- COPY TO PROGRAM, can create SECURITY DEFINER functions as any role.\n",[63,2914,2915],{"class":65,"line":127},[63,2916,103],{"emptyLinePlaceholder":102},[63,2918,2919],{"class":65,"line":133},[63,2920,2921],{"class":69},"-- ✅ RIGHT: app connects as a dedicated role with minimal privileges\n",[63,2923,2924,2926,2928,2931,2933,2935,2937],{"class":65,"line":148},[63,2925,77],{"class":76},[63,2927,80],{"class":76},[63,2929,2930],{"class":83}," app_role ",[63,2932,45],{"class":76},[63,2934,89],{"class":76},[63,2936,229],{"class":92},[63,2938,2939],{"class":83}," NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION NOBYPASSRLS;\n",[63,2941,2942,2944,2947,2949,2952,2955,2957],{"class":65,"line":153},[63,2943,136],{"class":76},[63,2945,2946],{"class":76}," CONNECT",[63,2948,167],{"class":76},[63,2950,2951],{"class":76}," DATABASE",[63,2953,2954],{"class":83}," mydb ",[63,2956,142],{"class":76},[63,2958,574],{"class":83},[63,2960,2961,2963,2966,2968,2970,2972,2974],{"class":65,"line":159},[63,2962,136],{"class":76},[63,2964,2965],{"class":83}," USAGE ",[63,2967,744],{"class":76},[63,2969,176],{"class":76},[63,2971,649],{"class":83},[63,2973,142],{"class":76},[63,2975,574],{"class":83},[63,2977,2978,2980,2982,2984,2986,2988,2990,2992,2994,2996,2998,3000,3002],{"class":65,"line":186},[63,2979,136],{"class":76},[63,2981,164],{"class":76},[63,2983,558],{"class":83},[63,2985,386],{"class":76},[63,2987,558],{"class":83},[63,2989,399],{"class":76},[63,2991,167],{"class":76},[63,2993,170],{"class":83},[63,2995,173],{"class":76},[63,2997,176],{"class":76},[63,2999,649],{"class":83},[63,3001,142],{"class":76},[63,3003,574],{"class":83},[63,3005,3006,3008,3010,3012,3014,3016],{"class":65,"line":192},[63,3007,281],{"class":76},[63,3009,825],{"class":76},[63,3011,828],{"class":83},[63,3013,173],{"class":76},[63,3015,176],{"class":76},[63,3017,835],{"class":83},[63,3019,3020,3022,3024,3026,3028,3030,3032,3034,3036,3038],{"class":65,"line":198},[63,3021,840],{"class":76},[63,3023,164],{"class":76},[63,3025,558],{"class":83},[63,3027,386],{"class":76},[63,3029,558],{"class":83},[63,3031,399],{"class":76},[63,3033,167],{"class":76},[63,3035,855],{"class":83},[63,3037,142],{"class":76},[63,3039,574],{"class":83},[63,3041,3042],{"class":65,"line":689},[63,3043,3044],{"class":69},"-- If compromised: the attacker can read\u002Finsert\u002Fupdate app tables.\n",[63,3046,3047],{"class":65,"line":695},[63,3048,3049],{"class":69},"-- They CANNOT drop the database, read password hashes, bypass RLS,\n",[63,3051,3052],{"class":65,"line":701},[63,3053,3054],{"class":69},"-- or escalate to other roles. Blast radius is limited.\n",[32,3056,3058],{"id":3057},"public-role-revoke-default-access","PUBLIC Role — revoke default access",[51,3060,3061],{"language":53},[55,3062,3064],{"className":57,"code":3063,"language":53,"meta":59,"style":59},"-- PUBLIC is a pseudo-role that represents ALL roles.\n-- PostgreSQL grants some access to PUBLIC by default:\n-- - CONNECT on databases\n-- - USAGE on public schema (pre-PG 15)\n-- - EXECUTE on all functions\n\n-- Revoke unwanted PUBLIC grants:\nREVOKE ALL ON DATABASE mydb FROM PUBLIC;          -- restrict who can connect\nGRANT CONNECT ON DATABASE mydb TO app_role;       -- re-grant to specific roles\n\n-- PG 15+: public schema no longer grants CREATE to PUBLIC by default.\n-- Pre-PG 15: revoke CREATE to prevent users from creating objects in public:\nREVOKE CREATE ON SCHEMA public FROM PUBLIC;\n\n-- Functions are EXECUTE-able by PUBLIC by default. For SECURITY DEFINER\n-- functions (which run as the owner), revoke PUBLIC and grant explicitly:\nREVOKE EXECUTE ON FUNCTION get_my_salary(BIGINT) FROM PUBLIC;\nGRANT EXECUTE ON FUNCTION get_my_salary(BIGINT) TO authenticated_users;\n",[23,3065,3066,3071,3076,3081,3086,3091,3095,3100,3120,3140,3144,3149,3154,3171,3175,3180,3185,3209],{"__ignoreMap":59},[63,3067,3068],{"class":65,"line":66},[63,3069,3070],{"class":69},"-- PUBLIC is a pseudo-role that represents ALL roles.\n",[63,3072,3073],{"class":65,"line":73},[63,3074,3075],{"class":69},"-- PostgreSQL grants some access to PUBLIC by default:\n",[63,3077,3078],{"class":65,"line":99},[63,3079,3080],{"class":69},"-- - CONNECT on databases\n",[63,3082,3083],{"class":65,"line":106},[63,3084,3085],{"class":69},"-- - USAGE on public schema (pre-PG 15)\n",[63,3087,3088],{"class":65,"line":112},[63,3089,3090],{"class":69},"-- - EXECUTE on all functions\n",[63,3092,3093],{"class":65,"line":122},[63,3094,103],{"emptyLinePlaceholder":102},[63,3096,3097],{"class":65,"line":127},[63,3098,3099],{"class":69},"-- Revoke unwanted PUBLIC grants:\n",[63,3101,3102,3104,3106,3108,3110,3112,3114,3117],{"class":65,"line":133},[63,3103,721],{"class":76},[63,3105,741],{"class":83},[63,3107,744],{"class":76},[63,3109,2951],{"class":76},[63,3111,2954],{"class":83},[63,3113,731],{"class":76},[63,3115,3116],{"class":83}," PUBLIC;          ",[63,3118,3119],{"class":69},"-- restrict who can connect\n",[63,3121,3122,3124,3126,3128,3130,3132,3134,3137],{"class":65,"line":148},[63,3123,136],{"class":76},[63,3125,2946],{"class":76},[63,3127,167],{"class":76},[63,3129,2951],{"class":76},[63,3131,2954],{"class":83},[63,3133,142],{"class":76},[63,3135,3136],{"class":83}," app_role;       ",[63,3138,3139],{"class":69},"-- re-grant to specific roles\n",[63,3141,3142],{"class":65,"line":153},[63,3143,103],{"emptyLinePlaceholder":102},[63,3145,3146],{"class":65,"line":159},[63,3147,3148],{"class":69},"-- PG 15+: public schema no longer grants CREATE to PUBLIC by default.\n",[63,3150,3151],{"class":65,"line":186},[63,3152,3153],{"class":69},"-- Pre-PG 15: revoke CREATE to prevent users from creating objects in public:\n",[63,3155,3156,3158,3161,3163,3165,3167,3169],{"class":65,"line":192},[63,3157,721],{"class":76},[63,3159,3160],{"class":76}," CREATE",[63,3162,167],{"class":76},[63,3164,176],{"class":76},[63,3166,649],{"class":83},[63,3168,731],{"class":76},[63,3170,2798],{"class":83},[63,3172,3173],{"class":65,"line":198},[63,3174,103],{"emptyLinePlaceholder":102},[63,3176,3177],{"class":65,"line":689},[63,3178,3179],{"class":69},"-- Functions are EXECUTE-able by PUBLIC by default. For SECURITY DEFINER\n",[63,3181,3182],{"class":65,"line":695},[63,3183,3184],{"class":69},"-- functions (which run as the owner), revoke PUBLIC and grant explicitly:\n",[63,3186,3187,3189,3192,3194,3197,3200,3202,3205,3207],{"class":65,"line":701},[63,3188,721],{"class":76},[63,3190,3191],{"class":76}," EXECUTE",[63,3193,167],{"class":76},[63,3195,3196],{"class":76}," FUNCTION",[63,3198,3199],{"class":83}," get_my_salary(",[63,3201,1968],{"class":76},[63,3203,3204],{"class":83},") ",[63,3206,731],{"class":76},[63,3208,2798],{"class":83},[63,3210,3211,3213,3215,3217,3219,3221,3223,3225,3227],{"class":65,"line":707},[63,3212,136],{"class":76},[63,3214,3191],{"class":76},[63,3216,167],{"class":76},[63,3218,3196],{"class":76},[63,3220,3199],{"class":83},[63,3222,1968],{"class":76},[63,3224,3204],{"class":83},[63,3226,142],{"class":76},[63,3228,3229],{"class":83}," authenticated_users;\n",[32,3231,3233],{"id":3232},"inspecting-permissions","Inspecting Permissions",[51,3235,3236],{"language":53},[55,3237,3239],{"className":57,"code":3238,"language":53,"meta":59,"style":59},"-- List privileges on a table (\\dp in psql)\nSELECT grantee, privilege_type\nFROM information_schema.role_table_grants\nWHERE table_name = 'orders'\nORDER BY grantee, privilege_type;\n\n-- List all roles and their memberships\nSELECT r.rolname AS role, m.rolname AS member\nFROM pg_auth_members am\nJOIN pg_roles r ON r.oid = am.roleid      -- the group role\nJOIN pg_roles m ON m.oid = am.member;     -- the member role\n\n-- Check if a role has a specific privilege\nSELECT has_table_privilege('app_role', 'orders', 'SELECT');  -- true\u002Ffalse\n\n-- List RLS policies on a table\nSELECT polname, polcmd, polqual, polwithcheck\nFROM pg_policy\nWHERE polrelid = 'orders'::regclass;\n",[23,3240,3241,3246,3253,3265,3278,3286,3290,3295,3326,3333,3363,3394,3398,3403,3429,3433,3438,3445,3452],{"__ignoreMap":59},[63,3242,3243],{"class":65,"line":66},[63,3244,3245],{"class":69},"-- List privileges on a table (\\dp in psql)\n",[63,3247,3248,3250],{"class":65,"line":73},[63,3249,373],{"class":76},[63,3251,3252],{"class":83}," grantee, privilege_type\n",[63,3254,3255,3257,3260,3262],{"class":65,"line":99},[63,3256,731],{"class":76},[63,3258,3259],{"class":294}," information_schema",[63,3261,2140],{"class":83},[63,3263,3264],{"class":294},"role_table_grants\n",[63,3266,3267,3270,3273,3275],{"class":65,"line":106},[63,3268,3269],{"class":76},"WHERE",[63,3271,3272],{"class":83}," table_name ",[63,3274,1210],{"class":76},[63,3276,3277],{"class":92}," 'orders'\n",[63,3279,3280,3283],{"class":65,"line":112},[63,3281,3282],{"class":76},"ORDER BY",[63,3284,3285],{"class":83}," grantee, privilege_type;\n",[63,3287,3288],{"class":65,"line":122},[63,3289,103],{"emptyLinePlaceholder":102},[63,3291,3292],{"class":65,"line":127},[63,3293,3294],{"class":69},"-- List all roles and their memberships\n",[63,3296,3297,3299,3302,3304,3307,3309,3312,3314,3317,3319,3321,3323],{"class":65,"line":133},[63,3298,373],{"class":76},[63,3300,3301],{"class":294}," r",[63,3303,2140],{"class":83},[63,3305,3306],{"class":294},"rolname",[63,3308,1977],{"class":76},[63,3310,3311],{"class":76}," role",[63,3313,558],{"class":83},[63,3315,3316],{"class":294},"m",[63,3318,2140],{"class":83},[63,3320,3306],{"class":294},[63,3322,1977],{"class":76},[63,3324,3325],{"class":83}," member\n",[63,3327,3328,3330],{"class":65,"line":148},[63,3329,731],{"class":76},[63,3331,3332],{"class":83}," pg_auth_members am\n",[63,3334,3335,3338,3341,3343,3345,3347,3350,3352,3355,3357,3360],{"class":65,"line":153},[63,3336,3337],{"class":76},"JOIN",[63,3339,3340],{"class":83}," pg_roles r ",[63,3342,744],{"class":76},[63,3344,3301],{"class":294},[63,3346,2140],{"class":83},[63,3348,3349],{"class":294},"oid",[63,3351,1610],{"class":76},[63,3353,3354],{"class":294}," am",[63,3356,2140],{"class":83},[63,3358,3359],{"class":294},"roleid",[63,3361,3362],{"class":69},"      -- the group role\n",[63,3364,3365,3367,3370,3372,3375,3377,3379,3381,3383,3385,3388,3391],{"class":65,"line":159},[63,3366,3337],{"class":76},[63,3368,3369],{"class":83}," pg_roles m ",[63,3371,744],{"class":76},[63,3373,3374],{"class":294}," m",[63,3376,2140],{"class":83},[63,3378,3349],{"class":294},[63,3380,1610],{"class":76},[63,3382,3354],{"class":294},[63,3384,2140],{"class":83},[63,3386,3387],{"class":294},"member",[63,3389,3390],{"class":83},";     ",[63,3392,3393],{"class":69},"-- the member role\n",[63,3395,3396],{"class":65,"line":186},[63,3397,103],{"emptyLinePlaceholder":102},[63,3399,3400],{"class":65,"line":192},[63,3401,3402],{"class":69},"-- Check if a role has a specific privilege\n",[63,3404,3405,3407,3410,3413,3415,3418,3420,3423,3426],{"class":65,"line":198},[63,3406,373],{"class":76},[63,3408,3409],{"class":83}," has_table_privilege(",[63,3411,3412],{"class":92},"'app_role'",[63,3414,558],{"class":83},[63,3416,3417],{"class":92},"'orders'",[63,3419,558],{"class":83},[63,3421,3422],{"class":92},"'SELECT'",[63,3424,3425],{"class":83},");  ",[63,3427,3428],{"class":69},"-- true\u002Ffalse\n",[63,3430,3431],{"class":65,"line":689},[63,3432,103],{"emptyLinePlaceholder":102},[63,3434,3435],{"class":65,"line":695},[63,3436,3437],{"class":69},"-- List RLS policies on a table\n",[63,3439,3440,3442],{"class":65,"line":701},[63,3441,373],{"class":76},[63,3443,3444],{"class":83}," polname, polcmd, polqual, polwithcheck\n",[63,3446,3447,3449],{"class":65,"line":707},[63,3448,731],{"class":76},[63,3450,3451],{"class":83}," pg_policy\n",[63,3453,3454,3456,3459,3461,3464],{"class":65,"line":712},[63,3455,3269],{"class":76},[63,3457,3458],{"class":83}," polrelid ",[63,3460,1210],{"class":76},[63,3462,3463],{"class":92}," 'orders'",[63,3465,3466],{"class":83},"::regclass;\n",[32,3468,3470],{"id":3469},"dropping-roles-reassign-ownership-first","Dropping Roles — reassign ownership first",[51,3472,3473],{"language":53},[55,3474,3476],{"className":57,"code":3475,"language":53,"meta":59,"style":59},"-- DROP ROLE fails if the role owns objects.\n-- Reassign ownership first, then drop:\nREASSIGN OWNED BY alice TO bob;    -- transfer alice's objects to bob\nDROP OWNED BY alice;               -- drop alice's remaining privileges\u002Fobjects\nDROP ROLE alice;                   -- now safe to drop\n",[23,3477,3478,3483,3488,3506,3522],{"__ignoreMap":59},[63,3479,3480],{"class":65,"line":66},[63,3481,3482],{"class":69},"-- DROP ROLE fails if the role owns objects.\n",[63,3484,3485],{"class":65,"line":73},[63,3486,3487],{"class":69},"-- Reassign ownership first, then drop:\n",[63,3489,3490,3493,3496,3498,3500,3503],{"class":65,"line":99},[63,3491,3492],{"class":83},"REASSIGN OWNED ",[63,3494,3495],{"class":76},"BY",[63,3497,84],{"class":83},[63,3499,142],{"class":76},[63,3501,3502],{"class":83}," bob;    ",[63,3504,3505],{"class":69},"-- transfer alice's objects to bob\n",[63,3507,3508,3511,3514,3516,3519],{"class":65,"line":106},[63,3509,3510],{"class":76},"DROP",[63,3512,3513],{"class":83}," OWNED ",[63,3515,3495],{"class":76},[63,3517,3518],{"class":83}," alice;               ",[63,3520,3521],{"class":69},"-- drop alice's remaining privileges\u002Fobjects\n",[63,3523,3524,3526,3528,3531],{"class":65,"line":112},[63,3525,3510],{"class":76},[63,3527,80],{"class":76},[63,3529,3530],{"class":83}," alice;                   ",[63,3532,3533],{"class":69},"-- now safe to drop\n",[32,3535,3537],{"id":3536},"tips-tricks","💡 Tips & Tricks",[3539,3540,3541,3565,3589,3607,3623,3657,3670,3686],"ul",{},[3542,3543,3544,3547,3548,3551,3552,558,3555,3558,3559,3561,3562,3564],"li",{},[18,3545,3546],{},"Idiom",": use ",[18,3549,3550],{},"group roles"," for access management — ",[23,3553,3554],{},"GRANT analytics_team TO alice",[23,3556,3557],{},"GRANT SELECT ON ... TO analytics_team",". Adding\u002Fremoving a user is ",[23,3560,136],{},"\u002F",[23,3563,721],{}," of the group role, not per-table grants. Group roles make access management O(teams) instead of O(users × tables).",[3542,3566,3567,3547,3569,3572,3573,3576,3577,3580,3581,3584,3585,3588],{},[18,3568,3546],{},[18,3570,3571],{},"RLS for multi-tenant isolation"," — a ",[23,3574,3575],{},"tenant_id"," column + an RLS policy (",[23,3578,3579],{},"USING tenant_id = current_setting('app.tenant', true)::bigint",") enforces isolation at the database level, immune to application bugs. The app sets ",[23,3582,3583],{},"app.tenant"," per request; every query is automatically scoped. Use ",[23,3586,3587],{},"current_setting(..., true)"," to return NULL instead of erroring when unset.",[3542,3590,3591,3593,3594,3597,3598,558,3600,3561,3602,3561,3604,3606],{},[18,3592,3546],{},": run the application as a ",[18,3595,3596],{},"dedicated non-owner role"," with minimal privileges (no superuser, no ",[23,3599,1105],{},[23,3601,373],{},[23,3603,386],{},[23,3605,399],{}," only on needed tables). The table owner and superuser bypass RLS — if the app connects as the owner, RLS is useless. Separate the migration role (owns tables, runs DDL) from the app role (data access, subject to RLS).",[3542,3608,3609,3547,3611,3614,3615,3618,3619,3622],{},[18,3610,3546],{},[23,3612,3613],{},"ALTER DEFAULT PRIVILEGES"," to grant on future tables — ",[23,3616,3617],{},"GRANT ON ALL TABLES"," covers existing tables only; without default privileges, every new table is invisible to the app until you grant on it (a common \"new table 403\" outage). Set ",[23,3620,3621],{},"DEFAULT PRIVILEGES FOR ROLE \u003Cmigrator>"," so tables created by the migration role auto-grant to the app role.",[3542,3624,3625,3628,3629,3632,3633,3636,3637,3639,3640,3642,3643,3645,3646,3649,3650,3653,3654,2140],{},[18,3626,3627],{},"Security",": revoke ",[23,3630,3631],{},"PUBLIC"," grants on databases, schemas, and ",[23,3634,3635],{},"SECURITY DEFINER"," functions — PostgreSQL grants ",[23,3638,472],{}," on databases and ",[23,3641,514],{}," on functions to ",[23,3644,3631],{}," by default. Revoke and grant explicitly to specific roles. Audit with ",[23,3647,3648],{},"\\dp+"," and ",[23,3651,3652],{},"\\df+"," in ",[23,3655,3656],{},"psql",[3542,3658,3659,3661,3662,3665,3666,3669],{},[18,3660,3627],{},": use a separate ",[18,3663,3664],{},"read-only role"," for analytics\u002Freporting — ",[23,3667,3668],{},"GRANT SELECT ON ... TO analytics_role",". Dashboards and BI tools connect as this role, preventing accidental writes. Combined with RLS, this limits both what analytics can see (rows) and what they can do (read only).",[3542,3671,3672,3674,3675,3678,3679,558,3682,3685],{},[18,3673,3546],{},": use column-level privileges for PII protection — ",[23,3676,3677],{},"GRANT SELECT (id, name, city) ON employees TO analytics_team"," hides ",[23,3680,3681],{},"salary",[23,3683,3684],{},"ssn",". For more complex column subsets or row filtering, use a view (cleaner, supports row filtering, can compute derived columns).",[3542,3687,3688,3547,3690,3693],{},[18,3689,3627],{},[23,3691,3692],{},"pg_hba.conf"," for connection-level security — restrict which IPs can connect, which databases, which roles, and enforce TLS. The database can't help if anyone can connect as any role from any IP.",[32,3695,3697],{"id":3696},"️-edge-cases-gotchas","⚠️ Edge Cases & Gotchas",[3539,3699,3700,3710,3725,3744,3755,3766,3782,3798,3811,3836,3852,3874,3885],{},[3542,3701,3702,3705,3706,3709],{},[18,3703,3704],{},"Table owner bypasses RLS",": by default, the owner of a table isn't subject to RLS policies. Use ",[23,3707,3708],{},"ALTER TABLE ... FORCE ROW LEVEL SECURITY"," to enforce RLS on the owner. Superusers always bypass (can't be changed). This is the #1 RLS bug: the app connects as the table owner, RLS silently doesn't apply.",[3542,3711,3712,3716,3717,3719,3720,3722,3723,2140],{},[18,3713,3714],{},[23,3715,1105],{},": a role with ",[23,3718,1105],{}," ignores all RLS policies. Don't grant ",[23,3721,1105],{}," to app roles. Reserve for migration\u002Fadmin roles that need to see all rows. Only superusers can set ",[23,3724,1105],{},[3542,3726,3727,3733,3734,3736,3737,3739,3740,3743],{},[18,3728,3729,3730],{},"RLS on views requires ",[23,3731,3732],{},"security_barrier",": a view over an RLS-protected table doesn't automatically prevent the view's caller from pushing predicates that leak information (e.g., a ",[23,3735,3269],{}," that errors on rows from other tenants). Create the view with ",[23,3738,3732],{},": ",[23,3741,3742],{},"CREATE VIEW my_view WITH (security_barrier) AS SELECT ...",". This prevents predicate pushdown past the view's boundary.",[3542,3745,3746,3739,3751,3754],{},[18,3747,3748,3750],{},[23,3749,29],{}," scope is per-creator",[23,3752,3753],{},"ALTER DEFAULT PRIVILEGES FOR ROLE alice"," applies only to tables created by alice. If bob creates a table, alice's defaults don't apply. Use a single migration role for all DDL, or set defaults for every role that creates objects.",[3542,3756,3757,3762,3763,3765],{},[18,3758,3759,3761],{},[23,3760,3617],{}," is a snapshot",": it applies to tables existing at grant time. New tables need ",[23,3764,3613],{}," or an explicit grant. This is the \"new table is invisible to the app\" bug.",[3542,3767,3768,3774,3775,3777,3778,3781],{},[18,3769,3770,3773],{},[23,3771,3772],{},"WITH GRANT OPTION"," spreads authorization",": a grantee with ",[23,3776,3772],{}," can grant to others — including roles you didn't intend. Avoid unless necessary. Use ",[23,3779,3780],{},"REVOKE ... CASCADE"," to undo a grant and all grants derived from it.",[3542,3783,3784,3739,3789,3791,3792,3794,3795,3797],{},[18,3785,3786,3788],{},[23,3787,3631],{}," is a role",[23,3790,3631],{}," represents all roles. Grants to ",[23,3793,3631],{}," apply to everyone (including future roles). Revoking from ",[23,3796,3631],{}," is how you remove default access (CONNECT on databases, EXECUTE on functions).",[3542,3799,3800,3739,3803,3806,3807,3810],{},[18,3801,3802],{},"Roles aren't dropped with their objects",[23,3804,3805],{},"DROP ROLE alice"," fails if alice owns objects. ",[23,3808,3809],{},"REASSIGN OWNED BY alice TO bob; DROP OWNED BY alice; DROP ROLE alice;"," reassigns ownership, drops remaining privileges, then drops the role.",[3542,3812,3813,3822,3823,3825,3826,3828,3829,3832,3833,3835],{},[18,3814,3815,3816,3561,3819],{},"Privilege inheritance with ",[23,3817,3818],{},"INHERIT",[23,3820,3821],{},"NO INHERIT",": by default, roles have ",[23,3824,3818],{}," — a member of a group automatically has the group's privileges. With ",[23,3827,3821],{},", the member must ",[23,3830,3831],{},"SET ROLE group_name"," to use the group's privileges. Use ",[23,3834,3821],{}," for roles that should have explicit privilege activation (auditing).",[3542,3837,3838,3739,3844,3847,3848,3851],{},[18,3839,3840,3843],{},[23,3841,3842],{},"current_setting"," errors if unset",[23,3845,3846],{},"current_setting('app.tenant')"," raises an error if the variable isn't set. Use ",[23,3849,3850],{},"current_setting('app.tenant', true)"," to return NULL instead. Handle NULL in the policy (NULL::bigint → no rows match → deny-by-default).",[3542,3853,3854,3857,3858,3861,3862,3865,3866,3869,3870,3873],{},[18,3855,3856],{},"Password in connection strings",": passwords in ",[23,3859,3860],{},"postgresql:\u002F\u002Fuser:pass@host\u002Fdb"," are visible in ",[23,3863,3864],{},"ps"," output, logs, and error messages. Use ",[23,3867,3868],{},"PGPASSWORD"," env var, ",[23,3871,3872],{},".pgpass"," file, or connection pools with server-side auth. Never commit connection strings to git.",[3542,3875,3876,3881,3882,3884],{},[18,3877,3878,3880],{},[23,3879,3613],{}," doesn't retroactively apply",": it affects only objects created AFTER the ALTER. Existing objects need an explicit ",[23,3883,3617],{},". Use both together for complete coverage.",[3542,3886,3887,3739,3890,3893,3894,3896,3897,3899,3900,3903],{},[18,3888,3889],{},"Sequence permissions are separate from table permissions",[23,3891,3892],{},"GRANT INSERT ON table"," does NOT grant ",[23,3895,497],{}," on the table's sequence. A role that can INSERT but can't ",[23,3898,506],{}," the sequence gets an error. ",[23,3901,3902],{},"GRANT USAGE, SELECT ON SEQUENCE seq TO role"," explicitly.",[32,3905,3907],{"id":3906},"spot-the-bug","🧠 Spot the Bug",[14,3909,3910],{},"A team enables RLS for multi-tenant isolation, but users report seeing data from other tenants. The RLS policy is correct. The setup:",[51,3912,3913],{"language":53},[55,3914,3916],{"className":57,"code":3915,"language":53,"meta":59,"style":59},"ALTER TABLE orders ENABLE ROW LEVEL SECURITY;\n\nCREATE POLICY tenant_isolation ON orders\n  FOR ALL\n  USING (tenant_id = current_setting('app.current_tenant', true)::bigint);\n\n-- The app connects as the table owner (a single \"app\" role that owns all tables)\n-- and sets app.current_tenant per request.\n-- Connection: postgresql:\u002F\u002Fapp_owner:pass@host\u002Fdb\n",[23,3917,3918,3936,3940,3952,3958,3976,3980,3985,3990],{"__ignoreMap":59},[63,3919,3920,3922,3924,3926,3928,3930,3932,3934],{"class":65,"line":66},[63,3921,281],{"class":76},[63,3923,1125],{"class":76},[63,3925,569],{"class":83},[63,3927,1130],{"class":76},[63,3929,1133],{"class":76},[63,3931,1136],{"class":76},[63,3933,1139],{"class":76},[63,3935,96],{"class":83},[63,3937,3938],{"class":65,"line":73},[63,3939,103],{"emptyLinePlaceholder":102},[63,3941,3942,3944,3946,3948,3950],{"class":65,"line":99},[63,3943,77],{"class":76},[63,3945,1172],{"class":76},[63,3947,2305],{"class":83},[63,3949,744],{"class":76},[63,3951,1180],{"class":83},[63,3953,3954,3956],{"class":65,"line":106},[63,3955,1185],{"class":76},[63,3957,2322],{"class":83},[63,3959,3960,3962,3964,3966,3968,3970,3972,3974],{"class":65,"line":112},[63,3961,1204],{"class":76},[63,3963,1696],{"class":83},[63,3965,1210],{"class":76},[63,3967,1213],{"class":83},[63,3969,2344],{"class":92},[63,3971,2347],{"class":83},[63,3973,1222],{"class":76},[63,3975,1225],{"class":83},[63,3977,3978],{"class":65,"line":122},[63,3979,103],{"emptyLinePlaceholder":102},[63,3981,3982],{"class":65,"line":127},[63,3983,3984],{"class":69},"-- The app connects as the table owner (a single \"app\" role that owns all tables)\n",[63,3986,3987],{"class":65,"line":133},[63,3988,3989],{"class":69},"-- and sets app.current_tenant per request.\n",[63,3991,3992],{"class":65,"line":148},[63,3993,3994],{"class":69},"-- Connection: postgresql:\u002F\u002Fapp_owner:pass@host\u002Fdb\n",[3996,3997,3998,4002,4021,4024,4130,4133,4139],"details",{},[3999,4000,4001],"summary",{},"Answer",[14,4003,4004,4005,4008,4009,4012,4013,4016,4017,4020],{},"The app connects as the ",[18,4006,4007],{},"table owner",", and by default, the ",[18,4010,4011],{},"table owner bypasses RLS",". So the ",[23,4014,4015],{},"tenant_isolation"," policy never applies — the app role sees all rows, regardless of ",[23,4018,4019],{},"app.current_tenant",". Users see data from all tenants.",[14,4022,4023],{},"Two fixes:",[51,4025,4026],{"language":53},[55,4027,4029],{"className":57,"code":4028,"language":53,"meta":59,"style":59},"-- Option 1: force RLS on the owner too\nALTER TABLE orders FORCE ROW LEVEL SECURITY;\n-- Now the owner is subject to policies. But superusers still bypass.\n\n-- Option 2 (BETTER): the app should connect as a NON-OWNER role.\n-- The owner role creates the schema (migrations); a separate app role\n-- (with grants, no ownership) runs queries. RLS applies to the app role.\nCREATE ROLE app_connection LOGIN PASSWORD '...' NOSUPERUSER NOBYPASSRLS;\nGRANT SELECT, INSERT, UPDATE, DELETE ON orders TO app_connection;\n-- Now the app connects as app_connection (not the owner).\n-- RLS applies automatically. FORCE RLS isn't needed.\n",[23,4030,4031,4036,4054,4059,4063,4068,4073,4078,4094,4120,4125],{"__ignoreMap":59},[63,4032,4033],{"class":65,"line":66},[63,4034,4035],{"class":69},"-- Option 1: force RLS on the owner too\n",[63,4037,4038,4040,4042,4044,4046,4048,4050,4052],{"class":65,"line":73},[63,4039,281],{"class":76},[63,4041,1125],{"class":76},[63,4043,569],{"class":83},[63,4045,1761],{"class":76},[63,4047,1133],{"class":76},[63,4049,1136],{"class":76},[63,4051,1139],{"class":76},[63,4053,96],{"class":83},[63,4055,4056],{"class":65,"line":99},[63,4057,4058],{"class":69},"-- Now the owner is subject to policies. But superusers still bypass.\n",[63,4060,4061],{"class":65,"line":106},[63,4062,103],{"emptyLinePlaceholder":102},[63,4064,4065],{"class":65,"line":112},[63,4066,4067],{"class":69},"-- Option 2 (BETTER): the app should connect as a NON-OWNER role.\n",[63,4069,4070],{"class":65,"line":122},[63,4071,4072],{"class":69},"-- The owner role creates the schema (migrations); a separate app role\n",[63,4074,4075],{"class":65,"line":127},[63,4076,4077],{"class":69},"-- (with grants, no ownership) runs queries. RLS applies to the app role.\n",[63,4079,4080,4082,4084,4086,4088,4090,4092],{"class":65,"line":133},[63,4081,77],{"class":76},[63,4083,80],{"class":76},[63,4085,1890],{"class":83},[63,4087,45],{"class":76},[63,4089,89],{"class":76},[63,4091,229],{"class":92},[63,4093,1899],{"class":83},[63,4095,4096,4098,4100,4102,4104,4106,4108,4110,4112,4114,4116,4118],{"class":65,"line":148},[63,4097,136],{"class":76},[63,4099,164],{"class":76},[63,4101,558],{"class":83},[63,4103,386],{"class":76},[63,4105,558],{"class":83},[63,4107,399],{"class":76},[63,4109,558],{"class":83},[63,4111,411],{"class":76},[63,4113,167],{"class":76},[63,4115,569],{"class":83},[63,4117,142],{"class":76},[63,4119,1911],{"class":83},[63,4121,4122],{"class":65,"line":153},[63,4123,4124],{"class":69},"-- Now the app connects as app_connection (not the owner).\n",[63,4126,4127],{"class":65,"line":159},[63,4128,4129],{"class":69},"-- RLS applies automatically. FORCE RLS isn't needed.\n",[14,4131,4132],{},"Option 2 is the principled fix — the app role shouldn't own the tables. Ownership is for migrations\u002Fschema management; the app role is for data access. With a separate app role that has grants but not ownership, RLS applies automatically.",[14,4134,4135,4136,4138],{},"Also check: is the app role a superuser, or does it have ",[23,4137,1105],{},"? Both bypass RLS. The app role must be a regular role with no bypass privileges.",[14,4140,4141,4144,4145,4147,4148,4151],{},[18,4142,4143],{},"The lesson",": RLS doesn't apply to the table owner (by default) or superusers. For multi-tenant isolation, the app must connect as a non-owner, non-superuser role without ",[23,4146,1105],{}," — or you must ",[23,4149,4150],{},"FORCE ROW LEVEL SECURITY"," on every tenant-scoped table.",[4153,4154,4155],"style",{},"html pre.shiki code .sdCPZ, html code.shiki .sdCPZ{--shiki-default:#6A737D;--shiki-github-dark:#6A737D}html pre.shiki code .svdQ7, html code.shiki .svdQ7{--shiki-default:#D73A49;--shiki-github-dark:#F97583}html pre.shiki code .ssxIu, html code.shiki .ssxIu{--shiki-default:#24292E;--shiki-github-dark:#E1E4E8}html pre.shiki code .sJ6F3, html code.shiki .sJ6F3{--shiki-default:#032F62;--shiki-github-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}html.github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}html pre.shiki code .snvgF, html code.shiki .snvgF{--shiki-default:#005CC5;--shiki-github-dark:#79B8FF}html pre.shiki code .sIsaT, html code.shiki .sIsaT{--shiki-default:#6F42C1;--shiki-github-dark:#B392F0}",{"title":59,"searchDepth":73,"depth":73,"links":4157},[4158,4161,4162,4163,4164,4165,4170,4171,4172,4173,4174,4175,4176,4177,4178],{"id":34,"depth":73,"text":35,"children":4159},[4160],{"id":205,"depth":99,"text":206},{"id":342,"depth":73,"text":343},{"id":536,"depth":73,"text":537},{"id":776,"depth":73,"text":777},{"id":1019,"depth":73,"text":1020},{"id":1098,"depth":73,"text":1099,"children":4166},[4167,4168,4169],{"id":1472,"depth":99,"text":1473},{"id":1563,"depth":99,"text":1564},{"id":1727,"depth":99,"text":1728},{"id":1810,"depth":73,"text":1811},{"id":2763,"depth":73,"text":2764},{"id":2874,"depth":73,"text":2875},{"id":3057,"depth":73,"text":3058},{"id":3232,"depth":73,"text":3233},{"id":3469,"depth":73,"text":3470},{"id":3536,"depth":73,"text":3537},{"id":3696,"depth":73,"text":3697},{"id":3906,"depth":73,"text":3907},"Roles vs users (LOGIN), group roles, GRANT\u002FREVOKE, privilege table, DEFAULT PRIVILEGES for future objects, column-level privileges, Row-Level Security with multi-tenant isolation, BYPASSRLS, search_path hijacking — code-first reference with a multi-tenant SaaS security model and anti-patterns for over-broad grants and superuser app connections.","md",{},"\u002Fsql\u002F24-security-and-roles",{"title":5,"description":4179},"sql\u002F24-security-and-roles","ddO22IOcwvb7_or0aIZDnGtK6SxAak2fy1Jw96RgVtw",1789924654918]