From: Peter Eisentraut <peter_e@gmx.net>
To: pgsql-hackers@postgresql.org
Cc: Petr Jelinek <pjmodos@pjmodos.net>
Subject: Re: GRANT ON ALL IN schema
Date: Wed, 17 Jun 2009 16:44:53 +0300
Message-ID: <200906171644.53717.peter_e@gmx.net> (raw)
In-Reply-To: <4A38A956.8080600@pjmodos.net>
References: <4A37BF63.50008@pjmodos.net>
<4A37E122.8070303@pjmodos.net>
<4A38A956.8080600@pjmodos.net>
On Wednesday 17 June 2009 11:29:10 Petr Jelinek wrote:
> The patch allows "GRANT ON ALL TABLES/VIEWS/FUNCTIONS/SEQUENCES IN
> schemaname, schemaname2 TO username" and same thing for REVOKE.
> Words TABLES, VIEWS, FUNCTIONS and SEQUENCES were added as unreserved
> keywords. Unfortunately I was unable to create syntax with optional
> SCHEMA keyword after IN (shift/reduce conflicts), if it's needed maybe
> somebody with better bison knowledge might add it.
I think you should design this with a bit wider scope. Instead of just "all
tables in this schema", think "all tables satisfying some condition". It has
been requested, for example, to be able to grant on all tables that match a
pattern.
> Also since this patch introduces VIEWS as object with grantable
> privileges, I added GRANT ON VIEW foo syntax which is more or less
> synonymous to GRANT ON TABLE foo syntax. It felt weird to have GRANT ON
> ALL VIEWS but not GRANT ON VIEW.
As far as GRANT is concerned, a view is a table, so I would omit the
VIEW/VIEWS stuff completely.
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-hackers@postgresql.org
Cc: peter_e@gmx.net, pjmodos@pjmodos.net
Subject: Re: GRANT ON ALL IN schema
In-Reply-To: <200906171644.53717.peter_e@gmx.net>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox