Skip to content

proxy: plan row-secured PostgreSQL estimates with a generic plan #1093

Description

@babltiga

Context

#1092 stops the persisted cost estimate from leaking row-security bound values by dropping every plan node's detail (and raw_plan) whenever a row-security directive was applied. That is fail-closed but costs reviewers the predicate / index-condition text on exactly the queries that are row-secured.

Proposal

For PostgreSQL, plan the row-secured statement without the bound values so the plan shows $1 instead of the literal, and keep detail / raw_plan:

Evaluate the equivalent for the other relational planners (MySQL/MariaDB have no generic-plan EXPLAIN — likely stay on stripping / redaction).

Trade-offs

  • Row estimates for the RLS-filtered column become generic (selectivity guess), not specific to the submitter's value — affects estimated_rows, the estimated_rows / scan_type routing conditions and the AI prompt summary. Measure the drift before switching.
  • Needs a server-version probe per datasource.

Acceptance

  • A row-secured PostgreSQL estimate persists predicate text containing only placeholders; an integration test asserts the bound value appears nowhere in plan / raw_plan / the GET /queries/{id} response.
  • Non-RLS queries unchanged.
  • docs/05-backend.md → "Automatic pre-flight cost estimate" updated.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions