Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id 3187D634D42 for ; Wed, 17 Jun 2009 10:45:01 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 59544-08 for ; Wed, 17 Jun 2009 10:44:49 -0300 (ADT) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from mail.gmx.net (mail.gmx.net [213.165.64.20]) by mail.postgresql.org (Postfix) with SMTP id 93111634C98 for ; Wed, 17 Jun 2009 10:44:57 -0300 (ADT) Received: (qmail invoked by alias); 17 Jun 2009 13:44:54 -0000 Received: from fsgw.f-secure.com (EHLO fsopti579.localnet) [193.110.108.33] by mail.gmx.net (mp036) with SMTP; 17 Jun 2009 15:44:54 +0200 X-Authenticated: #495269 X-Provags-ID: V01U2FsdGVkX1/5FHBurVv5xGLUgW9bPmXI7rhuX5SnbtPeRLV/y1 FaI0i0raw0Fszh From: Peter Eisentraut To: pgsql-hackers@postgresql.org Subject: Re: GRANT ON ALL IN schema Date: Wed, 17 Jun 2009 16:44:53 +0300 User-Agent: KMail/1.11.2 (Linux/2.6.26-2-686; KDE/4.2.2; i686; ; ) Cc: Petr Jelinek References: <4A37BF63.50008@pjmodos.net> <4A37E122.8070303@pjmodos.net> <4A38A956.8080600@pjmodos.net> In-Reply-To: <4A38A956.8080600@pjmodos.net> MIME-Version: 1.0 Content-Type: Text/Plain; charset="iso-8859-15" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200906171644.53717.peter_e@gmx.net> X-Y-GMX-Trusted: 0 X-FuHaFi: 0.57 X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=0.129 tagged_above=0 required=5 tests=AWL=0.129 X-Spam-Level: X-Archive-Number: 200906/1046 X-Sequence-Number: 140101 On Wednesday 17 June 2009 11:29:10 Petr Jelinek wrote: > The patch allows "GRANT ON ALL TABLES/VIEWS/FUNCTIONS/SEQUENCES IN > schemaname, schemaname2 TO username" and same thing for REVOKE. > Words TABLES, VIEWS, FUNCTIONS and SEQUENCES were added as unreserved > keywords. Unfortunately I was unable to create syntax with optional > SCHEMA keyword after IN (shift/reduce conflicts), if it's needed maybe > somebody with better bison knowledge might add it. I think you should design this with a bit wider scope. Instead of just "all tables in this schema", think "all tables satisfying some condition". It has been requested, for example, to be able to grant on all tables that match a pattern. > Also since this patch introduces VIEWS as object with grantable > privileges, I added GRANT ON VIEW foo syntax which is more or less > synonymous to GRANT ON TABLE foo syntax. It felt weird to have GRANT ON > ALL VIEWS but not GRANT ON VIEW. As far as GRANT is concerned, a view is a table, so I would omit the VIEW/VIEWS stuff completely.