mirror of
https://github.com/postgres/postgres.git
synced 2025-07-28 23:42:10 +03:00
Create new ParseExprKind for use by policy expressions.
Policy USING and WITH CHECK expressions were using EXPR_KIND_WHERE for parse analysis, which results in inappropriate ERROR messages when the expression contains unsupported constructs such as aggregates. Create a new ParseExprKind called EXPR_KIND_POLICY and tailor the related messages to fit. Reported by Noah Misch. Reviewed by Dean Rasheed, Alvaro Herrera, and Robert Haas. Back-patch to 9.5 where RLS was introduced.
This commit is contained in:
@ -106,7 +106,7 @@ test_rls_hooks_permissive(CmdType cmdtype, Relation relation)
|
||||
e = (Node *) makeSimpleA_Expr(AEXPR_OP, "=", (Node *) n, (Node *) c, 0);
|
||||
|
||||
policy->qual = (Expr *) transformWhereClause(qual_pstate, copyObject(e),
|
||||
EXPR_KIND_WHERE,
|
||||
EXPR_KIND_POLICY,
|
||||
"POLICY");
|
||||
|
||||
policy->with_check_qual = copyObject(policy->qual);
|
||||
@ -160,7 +160,7 @@ test_rls_hooks_restrictive(CmdType cmdtype, Relation relation)
|
||||
e = (Node *) makeSimpleA_Expr(AEXPR_OP, "=", (Node *) n, (Node *) c, 0);
|
||||
|
||||
policy->qual = (Expr *) transformWhereClause(qual_pstate, copyObject(e),
|
||||
EXPR_KIND_WHERE,
|
||||
EXPR_KIND_POLICY,
|
||||
"POLICY");
|
||||
|
||||
policy->with_check_qual = copyObject(policy->qual);
|
||||
|
@ -3024,6 +3024,15 @@ CREATE RULE "_RETURN" AS ON SELECT TO t DO INSTEAD
|
||||
SELECT * FROM generate_series(1,5) t0(c); -- succeeds
|
||||
ROLLBACK;
|
||||
--
|
||||
-- Policy expression handling
|
||||
--
|
||||
BEGIN;
|
||||
SET row_security = FORCE;
|
||||
CREATE TABLE t (c) AS VALUES ('bar'::text);
|
||||
CREATE POLICY p ON t USING (max(c)); -- fails: aggregate functions are not allowed in policy expressions
|
||||
ERROR: aggregate functions are not allowed in policy expressions
|
||||
ROLLBACK;
|
||||
--
|
||||
-- Clean up objects
|
||||
--
|
||||
RESET SESSION AUTHORIZATION;
|
||||
|
@ -1289,6 +1289,15 @@ CREATE RULE "_RETURN" AS ON SELECT TO t DO INSTEAD
|
||||
SELECT * FROM generate_series(1,5) t0(c); -- succeeds
|
||||
ROLLBACK;
|
||||
|
||||
--
|
||||
-- Policy expression handling
|
||||
--
|
||||
BEGIN;
|
||||
SET row_security = FORCE;
|
||||
CREATE TABLE t (c) AS VALUES ('bar'::text);
|
||||
CREATE POLICY p ON t USING (max(c)); -- fails: aggregate functions are not allowed in policy expressions
|
||||
ROLLBACK;
|
||||
|
||||
--
|
||||
-- Clean up objects
|
||||
--
|
||||
|
Reference in New Issue
Block a user