Row level security issue.
For a dataset with RLS implemented and when we add user as a workspace member, the RLS doesn't work which is expected and the user should be given Viewer role but when we add user as a member by mistake and when we change the access to viewer, still RLS doesn't work.
If we wait for couple of days, the RLS will be implemented correctly and resolves the issue by itself without any changes.
Is this an expected behavior or please provide any further insights on this.
2 Comments
- AnonymousNot applicable
To give more information on the issue:
Recap : A user who is given MEMBER rôle in a workspace, will retain this rôle even after changing it to VIEWER.
reproducing the bug :
1)Implement RLS and add a user to this RLS policy.
2) Add user to the workspace as MEMBER and save : this is the easy mistake, because the default dropdownbox choice is MEMBER
3)Change rôle from MEMBER to VIEWER.
4) Impersonate the user on RLS, now the RLS filter is failing.
Solution : Remove the user from workspace.
Wait several days(not sure how many).
Add user as VIEWER. and behold, RLS is functioniong.
- fbcideas_migusrNew MemberStatus added:New
Recent ideas
Dynamic ADLS-Gen2 path input for Spark Jobs Main definition file
I would like the ability to add a dynamic input box on a spark job definition's "Main Definition File" "ADLS-Gen2 path". this would be useful to set base and variable paths across all spark jobs...mfink_db39 minutes agoNew MemberNew226Views2likes2CommentsReintroduce Tenant/Capacity Switch to Control "Users can create Plan items" Post-GA
During the Preview phase of Fabric Plan items, administrators had access to a dedicated tenant/capacity setting: "Users can create Plan items". With General Availability (GA), this granular administr...Sri-Surendra_Ku3 hours agoNew MemberNew101Views14likes1CommentSupport Fabric SQL Database with workspace-level inbound Private Link
Fabric SQL Database supports tenant-level Private Link but not workspace-level Private Link. Securing a small number of databases therefore requires enabling Private Link across the entire tenant, in...WorkFull225 hours agoAdvocate INew10Views1like0CommentsImprove Relationship UI Wording to Better Reflect Filter Propagation Direction
The current relationship dialog can be confusing because the UI labels "From" and "To" do not always align with users' linguistic expectations regarding filter propagation. As per document : Relation...v-varunvv5 hours agoMicrosoft EmployeeNew18Views4likes0Comments