Repository navigation
Is PostgREST safe to expose publicly for a public database? #5273
Weastie
started this conversation in
Open-ended discussion
Replies: 2 comments
|
Hi, I would recommend you to go through PostgREST docs to learn about PostgREST in detail. |
0 replies
|
Hi there, I've seen open data projects over the years (recent one https://github.com/datagouv/api-tabular), but I believe they always require login for querying data.
An extension like pg_plan_filter can block expensive queries before running but needs some fine-tuning. That being said, I don't think a db could handle public internet traffic unless you have some aggressive caching. We have some ideas on #4460 but there's nothing settled yet. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi all,
Wondering if PostgREST is a good way to expose a public database via API, assuming we allow anonymous access but the anonymous user only has read permissions (at the PostgreSQL level).
A reverse proxy in front of it can handle basic rate limiting, TLS, etc.
Or are there fundamental security or performance flaws that make this dangerous, i.e. too hard to block certain expensive queries, etc.?
Plus. any advice for either PostgreSQL or PostgREST config is appreciated :)
All reactions