Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id 8014C63546B for ; Wed, 17 Jun 2009 11:45:09 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 73931-09 for ; Wed, 17 Jun 2009 11:44:54 -0300 (ADT) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from mail.gmx.net (mail.gmx.net [213.165.64.20]) by mail.postgresql.org (Postfix) with SMTP id 3DB206325FC for ; Wed, 17 Jun 2009 11:44:28 -0300 (ADT) Received: (qmail invoked by alias); 17 Jun 2009 14:44:25 -0000 Received: from fsgw.f-secure.com (EHLO fsopti579.localnet) [193.110.108.33] by mail.gmx.net (mp055) with SMTP; 17 Jun 2009 16:44:25 +0200 X-Authenticated: #495269 X-Provags-ID: V01U2FsdGVkX1/o1vgBfKzoHqGdW1i8Qnx9qkMHhcjzJgvuJa72du LFj8BeYd11kpWE From: Peter Eisentraut To: pgsql-hackers@postgresql.org Subject: Re: GRANT ON ALL IN schema Date: Wed, 17 Jun 2009 17:44:24 +0300 User-Agent: KMail/1.11.2 (Linux/2.6.26-2-686; KDE/4.2.2; i686; ; ) Cc: Tom Lane , Petr Jelinek References: <4A37BF63.50008@pjmodos.net> <200906171644.53717.peter_e@gmx.net> <25515.1245248104@sss.pgh.pa.us> In-Reply-To: <25515.1245248104@sss.pgh.pa.us> MIME-Version: 1.0 Content-Type: Text/Plain; charset="iso-8859-15" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200906171744.24456.peter_e@gmx.net> X-Y-GMX-Trusted: 0 X-FuHaFi: 0.57 X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=0.12 tagged_above=0 required=5 tests=AWL=0.120 X-Spam-Level: X-Archive-Number: 200906/1058 X-Sequence-Number: 140113 On Wednesday 17 June 2009 17:15:04 Tom Lane wrote: > Peter Eisentraut writes: > > I think you should design this with a bit wider scope. Instead of just > > "all tables in this schema", think "all tables satisfying some > > condition". It has been requested, for example, to be able to grant on > > all tables that match a pattern. > > I'm against that. Functionality of that sort is available now if you > really need it (write a plpgsql loop around an EXECUTE) and it's fairly > hard to see a clean syntax that is significantly more general than > "GRANT ON schema.*". In particular I strongly advise against getting > into supporting user-defined predicates in GRANT. There are good > reasons for not having utility statements evaluate random expressions. Why don't we tell people to write a plpgsql loop for the schema.* case as well? I haven't seen any evidence that the schema.* case is more common than other bulk DDL cases like "matches pattern" or "owned by $user" or "grant on all functions that are not security definer" etc.