agora inbox for pgsql-admin@postgresql.org
help / color / mirror / Atom feedFrom: Laurenz Albe <laurenz.albe@cybertec.at>
To: Scott Ribe <scott_ribe@elevated-dev.com>
To: Ron Johnson <ronljohnsonjr@gmail.com>
Cc: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Subject: Re: REVOKE ALL ON ALL OBJECTS IN ALL SCHEMAS FROM some_role?
Date: Tue, 08 Jul 2025 14:53:03 +0200
Message-ID: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at> (raw)
In-Reply-To: <D1C4B519-67B6-446A-92DF-A33D095FD215@elevated-dev.com>
References: <CANzqJaDu+7q9i=-vwUsX-ZZRTKSCCCG7FVF32X7XhPo1E4Xpxg@mail.gmail.com>
<D1C4B519-67B6-446A-92DF-A33D095FD215@elevated-dev.com>
On Tue, 2025-07-08 at 06:16 -0600, Scott Ribe wrote:
> I don't have an answer for you, just a question out of curiosity. Is this a prelude
> to dropping the role? Thus, if it existed, DROP ROLE ... CASCADE would have worked
> for your use case?
If dropping the role is the reason why the privileges should go, the canonical
procedure is:
- connect to each database in the cluster in turn; in each:
- REASSIGN OWNED BY role_to_drop ...
to transfer ownership
- DROP OWNED BY role_to_drop
to remove owned objects *and privileges*
- DROP ROLE role_to_drop
Yours,
Laurenz Albe
view thread (9+ messages) latest in thread
Message-ID: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at>
Permalink: ../bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at/
Also on: postgresql.org/message-id/bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-admin@postgresql.org
Cc: laurenz.albe@cybertec.at, scott_ribe@elevated-dev.com, ronljohnsonjr@gmail.com, pgsql-admin@lists.postgresql.org
Subject: Re: REVOKE ALL ON ALL OBJECTS IN ALL SCHEMAS FROM some_role?
In-Reply-To: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox