A nice list but I'd also add row-level security (RLS): https://info.crunchydata.com/blog/a-postgresql-row-level-sec...
It's amazing how much effort we put into restricting access on the server, but ignore user roles on the data layer.
It's amazing how much effort we put into restricting access on the server, but ignore user roles on the data layer.
The end result is that column, much less row, level controls end up unused in most cases.
Very security conscious places may just use stored procedures for everything, and limit access to those.
Edit: it’s not the same thing but fwiw pg row level security is completely decoupled from the dbms access control.
That's one of the reasons PostgREST seems promising to me. http://postgrest.org
It definitely introduced me to RLS though.