Changelog
What changed in each release, newest first. An alpha (0.1.0-alpha.1) is for trying a version early: it may still change before that version is released. Before 1.0, a minor release (0.2.0) may change the policy language, the authz.* functions, the SDKs and the file formats: what to do about it is under Upgrading. Each release upgrades from the one before it. How releases are numbered and made: RELEASING.md.
Unreleased
0.1.0 (alpha)
rowfence is now rowstile, and 0.1.0-alpha.2 is its first release under the new name (0.1.0-alpha.1 was published as rowfence, and those packages stay at that version). Another product, a proxy for DuckDB, was already called Rowfence, so the project takes a name of its own. The command is rowstile, the packages are rowstile on PyPI and npm and @rowstile/*, the image is ghcr.io/rowstile/rowstile, the docs are at https://rowstile.dev, and the repository is github.com/rowstile/rowstile. The policy language, the authz schema, the authz.* functions, .authz files and the AZ error codes keep their names; Upgrading below says what to change.
The first release, as an alpha: for trying rowstile early. Anything in it may still change before 0.1.0 (what a 0.x release promises). It holds:
- The policy language (
.authz): types read from the app's tables, relations from their columns and link tables, permissions built withand,orandnotand inherited down trees, rules for each table and command, column rules and masked columns, conditions in SQL, custom roles, shares that expire or carry conditions, scopes, invariants and tests. - The
rowstilecommand: compiles a policy into views, trigger-maintained inheritance tables, row-level security policies andauthz.*functions, applied as the tables' owner, with no extension and no superuser. Each change to the policy is a migration for Alembic, Prisma, Drizzle Kit, plain SQL, goose, dbmate or Flyway. Beside it:init,dev,test(with coverage),prove,review,diff,why,fmt,lint,indexes,plans,bench,graph, the generated clients, Studio, the language server and an MCP server for coding agents. - What apps call (
authz.*): signing in (act_as, API keys, JWTs), checks and lists (can,list,perms_of), sharing, who has access and why, the audit trail and change feed, access requests, break-glass, access reviews and view-as. - The SDKs: Python (FastAPI, SQLAlchemy, psycopg, asyncpg, Alembic, pytest) and TypeScript (pg, postgres.js, Prisma, Drizzle, Next.js, React, Vitest).
- The review for pull requests: a GitHub action and a GitLab CI template that comment what a policy change does to access.
- Editors: VS Code, Zed, and a Tree-sitter grammar for Helix and Neovim.
PostgreSQL 16, 17 and 18. Installed with npm (the command with its own Python), pip or the Docker image: Installing.
What changed since 0.1.0-alpha.1:
Added
- The docs site, at https://rowstile.dev: the guides, the reference, the error codes and the playground, as of the latest release.
- The VS Code extension is published on Open VSX, as a preview, by the release workflow whenever its own version is new (VSCodium, Cursor, Gitpod and other editors install from there).
Changed
- The name: rowfence is rowstile (above). What it writes says rowstile: the hints of the errors the runtime raises (
rowstile help AZ709),rowstile graph's first line, the generated clients, the compiled SQL, and the comments that mark its own RLS policies and masked views in the database ('rowstile','rowstile masked view'). The SDKs still read the code from the hints of a database applied by rowfence. The problem bodies the SDKs write have theirtypeat rowstile.dev (https://rowstile.dev/problems/refused). - The Zed extension carries the licence in its own folder, as Zed's registry asks, and when
rowstileisn't on the PATH it points to the Installing page (the install lines it showed get the placeholder while only an alpha is published). - The compiler's script in the repository is
core/compile_policy.py(it wasauthzc.py).
Upgrading
- Install
rowstilein place ofrowfence:pip install --pre rowstile(orrowstile[fastapi], ...),npm i rowstile@nextand@rowstile/*in place of@rowfence/*; in Python,import rowstilein place ofimport rowfence. - Rename
rowfence.tomltorowstile.toml. Until then the command readsrowfence.tomland says so. The npm launcher readsROWFENCE_PYTHONwhenROWSTILE_PYTHONisn't set. The GitLab review template's variables areROWSTILE_REVIEW_TOKEN,ROWSTILE_VERSIONandROWSTILE_PACKAGE. - The next migration (
rowstile migrate) marks the RLS policies and masked views anew; until then the command still recognizes the marks rowfence wrote ('rowfence', and'authzc'before them). The nextrowstile clientrewrites the clients' first line.
Fixed
- The policies readers copy (the docs app, the cookbook, the example apps' policies and tests) are laid out as
rowstile fmtwrites them, sorowstile fmt --checkin CI passes on a copy; only spacing changed. - While only an alpha is published, a plain
pip install rowstilefinds nothing:rowstile initnow tells a Python app to addrowstile[...]>=its own version (which lets pip and uv take a pre-release), and the stack pages, the Python SDK's README andllms.txtask for the alpha (--pre,rowstile@next,uv add --prerelease=allow).