kx1

kx1

Encrypting user provided Postgre creds & Encrypting dynamically created SQL tables

Hello everyone,

I’m creating an app which, has a part very similar to Airtable or Notion’s databases.

The app allows users to create SQL tables through a GUI. These tables are either stored in our DB or in the user’s DB if they provide the connection details.

When the user creates a table in our DB, I first create a user and schema in Postgre and I create the table in the schema. I want users to be able to directly connect to the DB to fetch their tables (this could allow them to use their tables in Power BI, for example), and with schemas I can grant them access to their tables and block them from accessing others.

I have two problems:

  1. Right now I’m storing the connection details of the user’s DB in plain text and I’d like to know your opinion on what’s the best way to encrypt the conn details.

As a note, the DB connection details belong to a group of users, so all users in the group must be able to decrypt the connection details. (So a group has many users and has many connection details)

  1. Ideally I’d like to encrypt our DB in a way that only the users can access their data, essentially blocking ourselves from accessing the user’s data. I perform ordering, filtering, etc on these tables so the encryption should still allow these operations.

I’m sure there’s a way to do #1 but not so sure about #2.

Everything is done with Ecto.

Any ideas on how to approach it?

Thank you in advanced!

Marked As Solved

dimitarvp

dimitarvp

Last Post!

kx1

kx1

Hey @dimitarvp, thanks for the quick reply. Yes, Cloak.Ecto looks like the perfect solution for my first problem. It does’t support User specific encryption keys out of the box, but it says in the docs that it can be implemented :+1:

Any ideas on how I could encrypt the table? With Cloak I think I can’t do it, because for filtering they recommend adding a mirrored hash field, but that’s only good for direct matching, if I want to do something like where string contains x or ordering by a date for example, I won’t be able to do it.

Where Next?

Trending in Questions Top

lanycrost
Hi everyone! I need implement if…else if…else condition from my elixir code, and anymore of this control flow structures not work proper...
New
senggen
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1] 15:22:35.803 [error] gen_event {lager_file_backend...
New
hariharasudhan94
Lets say I have map like this fetching from my database %{"_id" => #BSON.ObjectId<58eb1a7a9ad169198c3dXXXX>, "email" => ...
New
tj0
I’ve been following the steps here for the upgrade from 1.6 to 1.7 and it has gone relatively smoothly all the way till the phoenix_view ...
New
cgraham
Hi! What is currently the best library/method for parsing text and tabular data out of PDF files in Elixir or Erlang?
New
stefanchrobot
Hi, I need a way to handle data migrations in my application. I found an article by @wojtekmach about manual migrations: Automatic and ma...
New
stjefim
Hello! Suppose you are building workflow (order / task / payment) processing system with the following requirements: Each workflow con...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
kip
Localize is the next generation localisation library for Elixir. Think of it as ex_cldr version 3.0. The first version will be released ...
New
webofbits
Squid Mesh is an open source workflow automation runtime for Elixir applications. It is aimed at Phoenix and OTP apps that want to defin...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
kip
In 2021 I started a new library called Tempo with the objective of modelling time as a set of intervals - not as instants. In 2022 I gave...
New

We're in Beta

About us Mission Statement