pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Greg Stark <gsstark@mit.edu>
To: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Simon Riggs <simon@2ndquadrant.com>
Cc: Petr Jelinek <pjmodos@pjmodos.net>
Cc: PostgreSQL-development <pgsql-hackers@postgresql.org>
Subject: Re: GRANT ON ALL IN schema
Date: Tue, 7 Jul 2009 18:10:13 +0100
Message-ID: <407d949e0907071010v71e2bafam6d5fc6ae56e2fed5@mail.gmail.com> (raw)
In-Reply-To: <7045.1246979795@sss.pgh.pa.us>
References: <4A37BF63.50008@pjmodos.net>
	<4A37E122.8070303@pjmodos.net>
	<4A38A956.8080600@pjmodos.net>
	<4A4DE104.8090605@pjmodos.net>
	<1246963514.3874.156.camel@ebony.2ndQuadrant>
	<7045.1246979795@sss.pgh.pa.us>

On Tue, Jul 7, 2009 at 4:16 PM, Tom Lane<tgl@sss.pgh.pa.us> wrote:
>
>> (I'm sure we can do something intelligent with privileges that don't
>> apply to all object types rather than just fail. e.g. UPDATE privilege
>> should be same as USAGE on a sequence.)
>
> Anything you do in that line will be an ugly kluge, and will tend to
> encourage insecure over-granting of privileges (ie GRANT ALL ON ALL
> OBJECTS ... what's the point of using permissions at all then?)

That seems a bit pessimistic. While I disagree with Simon's rule I
think you can get plenty of mileage out of a more conservative rule of
just granting the privilege to all objects for which that privilege is
defined. Especially when you consider that we allow listing multiple
privileges in a single command.

-- 
greg
http://mit.edu/~gsstark/resume.pdf



view thread (83+ messages)  latest in thread

Message-ID: <407d949e0907071010v71e2bafam6d5fc6ae56e2fed5@mail.gmail.com>
Permalink:  ../407d949e0907071010v71e2bafam6d5fc6ae56e2fed5@mail.gmail.com/
Also on:    postgresql.org/message-id/407d949e0907071010v71e2bafam6d5fc6ae56e2fed5@mail.gmail.com

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: gsstark@mit.edu, tgl@sss.pgh.pa.us, simon@2ndquadrant.com, pjmodos@pjmodos.net
  Subject: Re: GRANT ON ALL IN schema
  In-Reply-To: <407d949e0907071010v71e2bafam6d5fc6ae56e2fed5@mail.gmail.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox