rowstile

io.github.rowstilev0.1.0-alpha.5更新於 Oct 6, 2026

Check, test, prove and review a rowstile policy: access rules for Postgres row-level security

概覽

AI 產生的概覽

讓助理檢查、測試、證明並審查 rowstile 政策檔,該政策會編譯成 Postgres 資料列層級安全性規則。

功能
rowstile 是本地命令列工具,會把描述「誰能做什麼」的小型政策檔編譯成純 SQL:檢視表、由觸發器維護的繼承表、資料列層級安全性政策,以及供應用程式碼使用的 authz 函式。這個 MCP 伺服器把該流程開放給助理,讓它能檢查、測試、證明並審查政策。每次變更都會以遷移形式交給應用程式既有的遷移工具,資料庫旁不需執行任何服務。
適用情境
當應用程式資料集中在單一 Postgres 資料庫,且某資料列的存取權取決於其他資料列(例如擁有者、巢狀團隊、資料夾或租戶)時適用;手寫的資料列層級安全性變得難以測試或修改時也適用。若存取決策分散在多個資料庫或 Postgres 之外,則不適用。
執行需求
以本地行程透過 stdio 在使用者機器上執行;僅限桌面,沒有網頁可執行版本。透過 npm 套件 rowstile 安裝(alpha 版本 0.1.0-alpha.5,需指定 next 標籤),自帶 Python;另有 pip 套件與 Docker 映像。未宣告任何驗證、環境變數或標頭。工具產生的遷移需要 Postgres 16、17 或 18 資料庫。
安裝前請注意
rowstile 是 0.x 預覽版,僅有一位維護者,且未經專案外稽核;在 1.0 之前,次要版本可能變更政策語言、authz 函式、SDK 與檔案格式。Docker 映像預設以 root 執行,除非傳入使用者參數。此工具會將遷移檔與 SQL 寫入專案,套用前應先審查產生的變更。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 rowstile,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

rowstile: access rules in a policy file, enforced by Postgres

Authorization inside your Postgres. Sharing, groups, nested folders and tenants, written in one policy file and compiled to row-level security. There is no authorization service to run beside the database, and no permission data to copy into one and keep in step: the rules read the tables your app already has.

Write who-can-do-what in one small file, next to the data it depends on. The rowstile command compiles it into plain SQL: views, trigger-maintained tables for inheritance, row-level security policies, and functions for app code: checks, sharing, "who has access", "why", access requests, reviews, audit. Each change to the policy ships as a migration for the tool your app already uses (Alembic, Prisma, Drizzle Kit, plain SQL). Nothing is installed in the database first, and nothing has to run next to it: any Postgres 16, 17 or 18 works, managed or not, and the owner of your tables runs the migrations, no superuser needed.

authz
app role app_user                               -- the Postgres role the app connects astype user = app.userstype folder = app.folders  owner  : user   = owner_id                    -- a relation read from a column  parent : folder = parent_id  editor : user   = app.folder_editors(folder_id -> user_id)   -- ... or from a link table  can edit = owner or editor or parent.edit     -- inherited down the tree  can view = editrules app.folders  select : view  update : edit

The app says who is asking in each transaction and queries its tables as usual; RLS filters every read and checks every write:

sql
BEGIN;SELECT authz.act_as('user', '42');         -- a trusted backend, or:-- SELECT authz.login_key('ak_...');       -- an API key (optionally limited by scopes)-- SELECT authz.login_jwt('eyJ...');       -- a JWT from your identity providerSELECT * FROM app.folders;                             -- only the folders 42 may viewSELECT authz.can('folder', 7, 'edit');                 -- ask directlySELECT * FROM authz.perms_of('folder', ARRAY['7', '8']);  -- a list's buttons, in one callCOMMIT;

Is it for you?

It fits when:

  • your app's data is in one Postgres database;
  • who may see or change a row depends on other rows: its owner, the members of a team (teams inside teams), a folder or a project that passes access down, a tenant, what people share with each other;
  • you were about to add an authorization service and keep it in step with the database, or your hand-written row-level security has become hard to test and to change.

It doesn't when:

  • what decides access is in several databases, or outside Postgres;
  • a browser reads the tables through Supabase's Data API (its roles are not the app role: a backend has to sign in);
  • one tree takes many moves and links a second (they wait for each other);
  • you need an outside audit or a vendor behind it today: rowstile is a 0.x preview with one maintainer.

Status

rowstile is a 0.x preview. Until 1.0, a minor release may change the language, the authz.* functions, the SDKs and the file formats; each release still upgrades a database from the one before it, and the changelog says what to do. What a 0.x release promises.

rowstile was called rowfence until 0.1.0-alpha.1; another product had the name first. The changelog says what to change.

Installing

Only an alpha is published so far, 0.1.0-alpha.5: ask for it.

npm i -D rowstile@next         # the command with its own Python: a TypeScript app needs nonepip install --pre rowstile     # the command and the Python SDK: rowstile[fastapi], [sqlalchemy], ...docker run --rm -u "$(id -u):$(id -g)" -v "$PWD:/work" ghcr.io/rowstile/rowstile:0.1.0-alpha.5 migrate

npm brings the Python for Linux (glibc and musl, x64 and arm64), macOS (x64 and arm64) and Windows x64. The image runs as root unless told otherwise: -u makes the files it writes yours. Installing has the rest: alphas and release candidates, the extras, the repository.

From this repository, put core/cli on PATH. rowstile init then finds the stack (Next.js, Prisma, Drizzle, FastAPI, SQLAlchemy, Alembic), writes rowstile.toml for its migration tool, adds the SDK's packages and says which line to change.

Docs

This repository

folderwhat
core/the compiler and the rowstile command, their tests and the benchmarks
sdk/the SDKs: Python (FastAPI, SQLAlchemy, psycopg, asyncpg) and TypeScript (Next.js, Prisma, Drizzle, pg, postgres.js, React)
integrations/each SDK's conformance suite: a small app and the checks it must pass
examples/complete apps built on rowstile: a file manager and a messenger
editor/the VS Code and Zed extensions, a Tree-sitter grammar (Helix, Neovim); other editors start rowstile lsp
review-ci/the policy review for pull requests: a GitHub action and a GitLab CI template
docs/the guides and the reference, as Markdown; site/ builds them into the docs site
playground/rowstile in the browser (Pyodide and PGlite)
packaging/how rowstile is installed: npm, PyPI and a Docker image

Contributing

A question, or something you built with rowstile: Discussions. Issues and pull requests are welcome: CONTRIBUTING.md says how a change gets in, and the code of conduct how we work together. What changed in each release: CHANGELOG.md. How releases are numbered and made: RELEASING.md.

Security

rowstile has not been audited by anyone outside the project. The threat model says what it protects and from whom. Report a vulnerability privately: SECURITY.md.

How the project itself is run, as the OpenSSF Scorecard measures it (pinned actions, what each workflow's token may do, known vulnerabilities in dependencies, review, releases): [OpenSSF Scorecard]

License

Apache License 2.0; see LICENSE. Copyright 2026 Salaheddine EL HSSANI.

來源:README.md,提交 6f24284

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0-alpha.5最新Oct 6, 2026