87 lines
6.8 KiB
XML
87 lines
6.8 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<svg xmlns="http://www.w3.org/2000/svg" width="860" height="300" viewBox="0 0 860 300" role="img" aria-labelledby="diagram-title diagram-description">
|
|
<title id="diagram-title">PostgreSQL RLS 적용 여부를 가르는 분기</title>
|
|
<desc id="diagram-description">PostgreSQL RLS를 세 개의 동시 전제로 보지 않는다. RLS가 활성화된 뒤 superuser 또는 BYPASSRLS인지, table owner인지와 FORCE RLS 여부를 확인한다. policy 대상 role에 applicable policy가 없으면 default deny이고, policy가 있으면 USING과 WITH CHECK를 평가한다.</desc>
|
|
<metadata>{"techviz":{"spec_version":"1.1","id":"rls-three-preconditions","profile":"two-zone-pipeline"},"source_context":{"document":"docs/clean-architecture-backend-template/final/document.md","document_sha256":"7c986b30b6ef3c12060b6749ee60d53e37d6994493d2703419732c9cab6077d8","anchor":{"kind":"line","value":7400,"line":7400}},"evidence_policy":"Each factual element cites source lines or is marked assumption.","diagram_only":true}</metadata>
|
|
<defs>
|
|
<marker id="arrow" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">
|
|
<path d="M 0 0 L 10 5 L 0 10 z" />
|
|
</marker>
|
|
<style>
|
|
:root { color-scheme: light; }
|
|
text { font-family: Inter, Pretendard, ui-sans-serif, system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif; fill: #111827; }
|
|
.canvas { fill: #ffffff; }
|
|
.group-box { fill: #ffffff; stroke: #9ca3af; stroke-width: 1.4; stroke-dasharray: 7 5; }
|
|
.group-label-bg { fill: #ffffff; }
|
|
.group-label { font-size: 13px; font-weight: 650; fill: #374151; }
|
|
.edge { fill: none; stroke: #374151; stroke-width: 1.8; stroke-linejoin: round; stroke-linecap: round; marker-end: url(#arrow); }
|
|
.edge.style-dashed, .edge.semantic-dashed, .edge.assumption { stroke-dasharray: 7 5; }
|
|
.edge.style-dotted { stroke-dasharray: 2 5; }
|
|
.edge.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.edge.emphasis-muted { stroke: #9ca3af; }
|
|
.edge.emphasis-warning, .edge.kind-failure, .edge.kind-error { stroke: #dc2626; stroke-width: 2.2; }
|
|
.edge-label-bg { fill: #ffffff; }
|
|
.edge-label { font-size: 12px; font-weight: 560; text-anchor: middle; }
|
|
.node-shape { fill: #ffffff; stroke: #4b5563; stroke-width: 1.7; }
|
|
.node-shape.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.node-shape.emphasis-muted { stroke: #9ca3af; fill: #f9fafb; }
|
|
.node-shape.emphasis-warning { stroke: #d97706; stroke-width: 2; fill: #fffdf5; }
|
|
.node-shape.kind-database, .node-shape.kind-datastore, .node-shape.kind-storage { fill: #f8fafc; }
|
|
.node-shape.kind-queue, .node-shape.kind-event, .node-shape.kind-topic { fill: #fafafa; }
|
|
.node-shape.assumption { stroke-dasharray: 4 4; }
|
|
.storage-bottom, .controller-divider { fill: none; stroke: #4b5563; stroke-width: 1.4; }
|
|
.controller-led { fill: #4b5563; }
|
|
.actor-symbol { fill: none; stroke: #4b5563; stroke-width: 1.8; stroke-linecap: round; }
|
|
.actor-symbol.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.node-label { font-size: 14px; font-weight: 650; text-anchor: middle; }
|
|
.node-role { font-size: 10px; letter-spacing: 0.04em; text-anchor: middle; fill: #6b7280; }
|
|
.node-detail-divider { stroke: #d1d5db; stroke-width: 1; }
|
|
.node-detail { font-size: 11px; fill: #374151; }
|
|
.assumption-badge { font-size: 9px; font-weight: 700; fill: #92400e; }
|
|
.failure-mark { stroke: #dc2626; stroke-width: 4; stroke-linecap: round; }
|
|
.lifeline { stroke: #9ca3af; stroke-width: 1.2; stroke-dasharray: 5 5; }
|
|
.timeline-axis { stroke: #374151; stroke-width: 1.8; marker-end: url(#arrow); }
|
|
.timeline-stem { stroke: #6b7280; stroke-width: 1.3; }
|
|
.timeline-marker { fill: #ffffff; stroke: #374151; stroke-width: 1.7; }
|
|
.timeline-marker.primary { fill: #2563eb; stroke: #2563eb; }
|
|
.timeline-marker.warning { fill: #dc2626; stroke: #dc2626; }
|
|
.timeline-label { font-size: 13px; font-weight: 650; text-anchor: middle; }
|
|
.timeline-detail { font-size: 11px; fill: #4b5563; text-anchor: middle; }
|
|
</style>
|
|
</defs>
|
|
<rect class="canvas" width="860" height="300" />
|
|
<rect class="group-box" x="45.0" y="49.0" width="470.0" height="177.0" rx="8" />
|
|
<rect class="group-label-bg" x="59.0" y="39.0" width="127.0" height="22" />
|
|
<text class="group-label" x="69.0" y="54.0">policy 적용 대상 판정</text>
|
|
<rect class="group-box" x="565.0" y="49.0" width="250.0" height="160.0" rx="8" />
|
|
<rect class="group-label-bg" x="579.0" y="39.0" width="113.0" height="22" />
|
|
<text class="group-label" x="589.0" y="54.0">policy 존재와 평가</text>
|
|
<polyline class="edge kind-request style-solid emphasis-normal" points="265.0,130.5 295.0,130.5 295.0,59.0 265.0,59.0 265.0,147.5 295.0,147.5" data-evidence="7400-7432" />
|
|
<rect class="edge-label-bg" x="242.4" y="17.0" width="58.2" height="22" rx="3" />
|
|
<text class="edge-label" x="271.5" y="32.0">RLS on</text>
|
|
<polyline class="edge kind-request style-solid emphasis-primary" points="485.0,147.5 540.0,147.5 540.0,139.0 595.0,139.0" data-evidence="7400-7432" />
|
|
<rect class="edge-label-bg" x="542.0" y="129.2" width="44.0" height="22" rx="3" />
|
|
<text class="edge-label" x="564.0" y="144.2">적용</text>
|
|
<g id="node-rls">
|
|
<rect class="node-shape kind-process emphasis-normal role-stage" data-evidence="7400-7432" x="75.0" y="95.0" width="190.0" height="71.0" rx="7" />
|
|
<text class="node-label" x="170.0" y="122.0">RLS 활성 여부</text>
|
|
<line class="node-detail-divider" x1="89.0" y1="143.0" x2="251.0" y2="143.0" />
|
|
<text class="node-detail" x="91.0" y="160.0">no → policy 미적용</text>
|
|
</g>
|
|
<g id="node-subject">
|
|
<rect class="node-shape kind-process emphasis-normal role-stage" data-evidence="7400-7432" x="295.0" y="95.0" width="190.0" height="105.0" rx="7" />
|
|
<text class="node-label" x="390.0" y="122.0">policy 적용 대상</text>
|
|
<line class="node-detail-divider" x1="309.0" y1="143.0" x2="471.0" y2="143.0" />
|
|
<text class="node-detail" x="311.0" y="160.0">superuser / BYPASSRLS → 우회</text>
|
|
<text class="node-detail" x="311.0" y="176.0">owner + FORCE off → 우회</text>
|
|
<text class="node-detail" x="311.0" y="192.0">non-owner 또는 owner + FORCE on → 대상</text>
|
|
</g>
|
|
<g id="node-policy">
|
|
<rect class="node-shape kind-process emphasis-primary role-stage" data-evidence="7400-7432" x="595.0" y="95.0" width="190.0" height="88.0" rx="7" />
|
|
<text class="node-label" x="690.0" y="122.0">applicable policy</text>
|
|
<line class="node-detail-divider" x1="609.0" y1="143.0" x2="771.0" y2="143.0" />
|
|
<text class="node-detail" x="611.0" y="160.0">none → default deny</text>
|
|
<text class="node-detail" x="611.0" y="176.0">exists → USING / WITH CHECK 평가</text>
|
|
</g>
|
|
</svg>
|