Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

295
Views
Are RLS policy definitions affected at runtime by the search_path?

While answering this question, I gave some (unfounded) advice on

create policy test_policy on policy for all to public using (
        user_id = session_user_id());

Btw, you should schema-qualify the session_user_id() call to make your policy actually secure, so that the user cannot inject their own session_user_id function through the search_path.

But is this actually the case? I had misremembered the search_path issue with SECURITY DEFINER functions.

How and when are row-level-security policies parsed? Are the references resolved during definition or during evaluation?

It would make sense to have identifiers in them be early-bound not late-bound, but I could not find anything in the docs about this.

over 4 years ago · Santiago Trujillo
1 answers
Answer question

0

Policy definitions are stored in pg_policy, where the USING clause is stored in the polqual column and the WITH CHECK expression is stored in polwithcheck.

Both columns are of data type pg_node_tree, which is a parsed SQL statement. So policies are parsed when they are created, not when they are executed, much like views or standard conforming SQL functions (new in v14). That means that the setting of search_path is only relevant when the policy is created, not when it is executed.

over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!