For the complete documentation index, see llms.txt. This page is also available as Markdown.

Permissions

How to manage tables read/writes

This guide will allow you to understand how pREST to understand and manage your table's permission management and how you can tailor it to your needs by using the prest.toml file.

Restrict mode

The prest.toml file allows you to configure each table's read/write/delete permissions.

[access]
restrict = true  # can access only the tables listed below

restrict = false: (default) The pREST will serve in public mode. You can write/read/delete every data without configuring permissions.

restrict = true: you need to configure the permissions of all tables.

Ignore table

If you need to ignore restricted access mode for some tables, you can use the ignore_table option, it receives a string list with the names of the tables to be "ignored", by default, is an empty list [].

[access]
restrict = true
ignore_table = ["news"]

Table permissions

Example:

[[access.tables]]
name = "test"
permissions = ["read", "write", "delete"]
fields = ["id", "name"]

When a database registry is active, use optional database and schema fields to scope permissions to a specific alias:

Permissions are matched against alias + schema + table name when the registry is configured. When database is omitted, the rule applies to all aliases (legacy behavior).

Multiple configurations for the same table:

attribute
description

name

Table name

database

Optional. Database alias when using a registry (#973)

schema

Optional. Schema name (default matching applies when omitted)

permissions

Table permissions. Options: read, write and delete

fields

Exposed fields permitted for operations

Per-database permissions

When a database registry is active, scope permissions to a specific alias and schema:

Permissions are matched against alias + schema + table name.

User-level permissions

v2 supports per-user table permissions via [[access.users]]. The authenticated user's identity (from the JWT sub claim or username) is matched against access.users.name.

User-level table permissions restrict or extend the global access.tables rules for that specific user.

Example:

In this example, user foo_read can only read the id and name fields on read_table, even if the global table permission allows more fields.

For a comprehensive example with multiple users and permission combinations, see testdata/prest.toml.

Example configuration

Configuration example: prest.toml

Last updated