Skip to content

AZ603: An inheritance condition that isn't the same for everyone at any time ​

What limits inheritance is stored in the tree, so Postgres must agree that it depends only on the row: the functions it calls are IMMUTABLE, and nothing depends on the time zone or the session. To read another table, use a subquery (its changes are then tracked), not a function that reads it.

Reported when the policy is applied (rowfence push, apply, a migration), against the database.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  parent : folder = parent_id
  can view = owner or (parent.view and {app.is_open(id)})

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  parent : folder = parent_id
  can view = owner or (parent.view and {not exists (select 1 from app.locks l where l.folder_id = id)})