Why not expose something similar to a prepared statement with the HTTP API? That lets you define input data types, and only queries that have been explicitly enabled could be run.
Why not expose something similar to a prepared statement with the HTTP API? That lets you define input data types, and only queries that have been explicitly enabled could be run.
What Postgres has in terms of validation is essentially a not terribly sophisticated type system, plus stored procedures in PL/pgSQL, Perl, Python or Tcl. These are frankly a pain to manage. In terms of security, well... outside of stored procedures, there is no special way of restricting a given connection/user to only rows with the right foreign key in a table. On the other hand, many web framework have some sort of authorization framework.
>In terms of security, well... outside of stored procedures, there is no special way of restricting a given connection/user to only rows with the right foreign key in a table
"If I specifically exclude the way to do this, there is no way to do this"? Also views work fine.
I would rather integrate user validation into normal queries, or have it handeled at the edge with an application firewall along with other kinds of input validation.
You could always do something like this...
INSERT INTO test
select %(inputdata)
where %(cookie) = hmac(%(userid), 'serverkey','sha256' )
and char_length(%(inputdata)) < 1000