For the complete documentation index, see llms.txt. This page is also available as Markdown.
Permissions
How to manage tables read/writes
This guide will allow you to understand how pREST to understand and manage your table's permission management and how you can tailor it to your needs by using the prest.toml file.
Restrict mode
The prest.toml file allows you to configure each table's read/write/delete permissions.
[access]restrict=true# can access only the tables listed below
restrict = false: (default) The pREST will serve in public mode. You can write/read/delete every data without configuring permissions.
restrict = true: you need to configure the permissions of all tables.
Ignore table
If you need to ignore restricted access mode for some tables, you can use the ignore_table option, it receives a string list with the names of the tables to be "ignored", by default, is an empty list [].
When a database registry is active, use optional database and schema fields to scope permissions to a specific alias:
Permissions are matched against alias + schema + table name when the registry is configured. When database is omitted, the rule applies to all aliases (legacy behavior).
Multiple configurations for the same table:
attribute
description
name
Table name
database
Optional. Database alias when using a registry (#973)
schema
Optional. Schema name (default matching applies when omitted)
permissions
Table permissions. Options: read, write and delete
fields
Exposed fields permitted for operations
Per-database permissions
When a database registry is active, scope permissions to a specific alias and schema:
Permissions are matched against alias + schema + table name.
User-level permissions
v2 supports per-user table permissions via [[access.users]]. The authenticated user's identity (from the JWT sub claim or username) is matched against access.users.name.
User-level table permissions restrict or extend the global access.tables rules for that specific user.
Example:
In this example, user foo_read can only read the id and name fields on read_table, even if the global table permission allows more fields.
For a comprehensive example with multiple users and permission combinations, see testdata/prest.toml.