rowstile

io.github.rowstilev0.1.0-alpha.5更新于 Oct 6, 2026

Check, test, prove and review a rowstile policy: access rules for Postgres row-level security

概览

AI 生成的概览

让助手检查、测试、证明并审查 rowstile 策略文件,该策略会编译为 Postgres 行级安全规则。

功能
rowstile 是一个本地命令行工具,把描述“谁能做什么”的小型策略文件编译成纯 SQL:视图、由触发器维护的继承表、行级安全策略,以及供应用代码使用的 authz 函数。该 MCP 服务器把这一流程开放给助手,使其能够检查、测试、证明并审查策略。每次变更都会作为迁移交给应用已有的迁移工具,数据库旁边无需运行任何服务。
适用场景
当应用数据集中在一个 Postgres 数据库中,且某行的访问权限取决于其他行(如所有者、嵌套团队、文件夹或租户)时适用;手写的行级安全策略变得难以测试或修改时也适用。若访问决策分散在多个数据库或 Postgres 之外,则不适用。
运行要求
以本地进程方式通过 stdio 在用户机器上运行;仅限桌面,无网页可执行版本。通过 npm 包 rowstile 安装(alpha 版本 0.1.0-alpha.5,需指定 next 标签),自带 Python;另有 pip 包和 Docker 镜像。未声明任何认证、环境变量或请求头。工具生成的迁移需要 Postgres 16、17 或 18 数据库。
安装前请注意
rowstile 是 0.x 预览版,仅有一位维护者,且未经项目外审计;在 1.0 之前,次要版本可能更改策略语言、authz 函数、SDK 和文件格式。Docker 镜像默认以 root 运行,除非传入用户参数。该工具会向项目写入迁移文件和 SQL,应用前应审查生成的变更。

安装

在 SourceWeft 中

  1. 打开 控制台中的 rowstile,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

rowstile: access rules in a policy file, enforced by Postgres

Authorization inside your Postgres. Sharing, groups, nested folders and tenants, written in one policy file and compiled to row-level security. There is no authorization service to run beside the database, and no permission data to copy into one and keep in step: the rules read the tables your app already has.

Write who-can-do-what in one small file, next to the data it depends on. The rowstile command compiles it into plain SQL: views, trigger-maintained tables for inheritance, row-level security policies, and functions for app code: checks, sharing, "who has access", "why", access requests, reviews, audit. Each change to the policy ships as a migration for the tool your app already uses (Alembic, Prisma, Drizzle Kit, plain SQL). Nothing is installed in the database first, and nothing has to run next to it: any Postgres 16, 17 or 18 works, managed or not, and the owner of your tables runs the migrations, no superuser needed.

authz
app role app_user                               -- the Postgres role the app connects astype user = app.userstype folder = app.folders  owner  : user   = owner_id                    -- a relation read from a column  parent : folder = parent_id  editor : user   = app.folder_editors(folder_id -> user_id)   -- ... or from a link table  can edit = owner or editor or parent.edit     -- inherited down the tree  can view = editrules app.folders  select : view  update : edit

The app says who is asking in each transaction and queries its tables as usual; RLS filters every read and checks every write:

sql
BEGIN;SELECT authz.act_as('user', '42');         -- a trusted backend, or:-- SELECT authz.login_key('ak_...');       -- an API key (optionally limited by scopes)-- SELECT authz.login_jwt('eyJ...');       -- a JWT from your identity providerSELECT * FROM app.folders;                             -- only the folders 42 may viewSELECT authz.can('folder', 7, 'edit');                 -- ask directlySELECT * FROM authz.perms_of('folder', ARRAY['7', '8']);  -- a list's buttons, in one callCOMMIT;

Is it for you?

It fits when:

  • your app's data is in one Postgres database;
  • who may see or change a row depends on other rows: its owner, the members of a team (teams inside teams), a folder or a project that passes access down, a tenant, what people share with each other;
  • you were about to add an authorization service and keep it in step with the database, or your hand-written row-level security has become hard to test and to change.

It doesn't when:

  • what decides access is in several databases, or outside Postgres;
  • a browser reads the tables through Supabase's Data API (its roles are not the app role: a backend has to sign in);
  • one tree takes many moves and links a second (they wait for each other);
  • you need an outside audit or a vendor behind it today: rowstile is a 0.x preview with one maintainer.

Status

rowstile is a 0.x preview. Until 1.0, a minor release may change the language, the authz.* functions, the SDKs and the file formats; each release still upgrades a database from the one before it, and the changelog says what to do. What a 0.x release promises.

rowstile was called rowfence until 0.1.0-alpha.1; another product had the name first. The changelog says what to change.

Installing

Only an alpha is published so far, 0.1.0-alpha.5: ask for it.

npm i -D rowstile@next         # the command with its own Python: a TypeScript app needs nonepip install --pre rowstile     # the command and the Python SDK: rowstile[fastapi], [sqlalchemy], ...docker run --rm -u "$(id -u):$(id -g)" -v "$PWD:/work" ghcr.io/rowstile/rowstile:0.1.0-alpha.5 migrate

npm brings the Python for Linux (glibc and musl, x64 and arm64), macOS (x64 and arm64) and Windows x64. The image runs as root unless told otherwise: -u makes the files it writes yours. Installing has the rest: alphas and release candidates, the extras, the repository.

From this repository, put core/cli on PATH. rowstile init then finds the stack (Next.js, Prisma, Drizzle, FastAPI, SQLAlchemy, Alembic), writes rowstile.toml for its migration tool, adds the SDK's packages and says which line to change.

Docs

This repository

folderwhat
core/the compiler and the rowstile command, their tests and the benchmarks
sdk/the SDKs: Python (FastAPI, SQLAlchemy, psycopg, asyncpg) and TypeScript (Next.js, Prisma, Drizzle, pg, postgres.js, React)
integrations/each SDK's conformance suite: a small app and the checks it must pass
examples/complete apps built on rowstile: a file manager and a messenger
editor/the VS Code and Zed extensions, a Tree-sitter grammar (Helix, Neovim); other editors start rowstile lsp
review-ci/the policy review for pull requests: a GitHub action and a GitLab CI template
docs/the guides and the reference, as Markdown; site/ builds them into the docs site
playground/rowstile in the browser (Pyodide and PGlite)
packaging/how rowstile is installed: npm, PyPI and a Docker image

Contributing

A question, or something you built with rowstile: Discussions. Issues and pull requests are welcome: CONTRIBUTING.md says how a change gets in, and the code of conduct how we work together. What changed in each release: CHANGELOG.md. How releases are numbered and made: RELEASING.md.

Security

rowstile has not been audited by anyone outside the project. The threat model says what it protects and from whom. Report a vulnerability privately: SECURITY.md.

How the project itself is run, as the OpenSSF Scorecard measures it (pinned actions, what each workflow's token may do, known vulnerabilities in dependencies, review, releases): [OpenSSF Scorecard]

License

Apache License 2.0; see LICENSE. Copyright 2026 Salaheddine EL HSSANI.

来源:README.md,提交 6f24284

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0-alpha.5最新Oct 6, 2026