agora inbox for pgsql-admin@postgresql.org  
help / color / mirror / Atom feed
From: Laurenz Albe <laurenz.albe@cybertec.at>
To: Scott Ribe <scott_ribe@elevated-dev.com>
To: Ron Johnson <ronljohnsonjr@gmail.com>
Cc: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Subject: Re: REVOKE ALL ON ALL OBJECTS IN ALL SCHEMAS FROM some_role?
Date: Tue, 08 Jul 2025 14:53:03 +0200
Message-ID: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at> (raw)
In-Reply-To: <D1C4B519-67B6-446A-92DF-A33D095FD215@elevated-dev.com>
References: <CANzqJaDu+7q9i=-vwUsX-ZZRTKSCCCG7FVF32X7XhPo1E4Xpxg@mail.gmail.com>
	<D1C4B519-67B6-446A-92DF-A33D095FD215@elevated-dev.com>

On Tue, 2025-07-08 at 06:16 -0600, Scott Ribe wrote:
> I don't have an answer for you, just a question out of curiosity. Is this a prelude
> to dropping the role? Thus, if it existed, DROP ROLE ... CASCADE would have worked
> for your use case?

If dropping the role is the reason why the privileges should go, the canonical
procedure is:

- connect to each database in the cluster in turn; in each:
  - REASSIGN OWNED BY role_to_drop ...
    to transfer ownership
  - DROP OWNED BY role_to_drop
    to remove owned objects *and privileges*
- DROP ROLE role_to_drop

Yours,
Laurenz Albe





view thread (9+ messages)  latest in thread

Message-ID: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at>
Permalink:  ../bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at/
Also on:    postgresql.org/message-id/bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: laurenz.albe@cybertec.at, scott_ribe@elevated-dev.com, ronljohnsonjr@gmail.com, pgsql-admin@lists.postgresql.org
  Subject: Re: REVOKE ALL ON ALL OBJECTS IN ALL SCHEMAS FROM some_role?
  In-Reply-To: <bacddcb84956a662cd3de97ce4fe32d705083dc7.camel@cybertec.at>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox