Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id 0B250634DC0 for ; Wed, 17 Jun 2009 11:54:01 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 76026-03-4 for ; Wed, 17 Jun 2009 11:53:48 -0300 (ADT) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from smtp-out4.iol.cz (smtp-out4.iol.cz [194.228.2.92]) by mail.postgresql.org (Postfix) with ESMTP id 1A92F6355E1 for ; Wed, 17 Jun 2009 11:53:43 -0300 (ADT) Received: from antivir6.iol.cz (unknown [192.168.30.215]) by smtp-out4.iol.cz (Postfix) with ESMTP id DA6B5CE451B; Wed, 17 Jun 2009 14:31:14 +0000 (UTC) Received: from localhost (antivir6.iol.cz [127.0.0.1]) by antivir6.iol.cz (Postfix) with ESMTP id C544072005A; Wed, 17 Jun 2009 16:31:14 +0200 (CEST) X-Virus-Scanned: amavisd-new at iol.cz Received: from antivir6.iol.cz ([127.0.0.1]) by localhost (antivir6.iol.cz [127.0.0.1]) (amavisd-new, port 10224) with LMTP id 76dcVpTcyKF2; Wed, 17 Jun 2009 16:31:14 +0200 (CEST) Received: from port4.iol.cz (unknown [192.168.30.94]) by antivir6.iol.cz (Postfix) with ESMTP id A2033720059; Wed, 17 Jun 2009 16:31:14 +0200 (CEST) X-SBRS: None X-SBRS-none: None X-RECVLIST: MTA-OUT-IOL X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: AjACAHubOEpYZzAw/2dsb2JhbAAI1TqECAU Received: from unknown (HELO [10.12.0.96]) ([88.103.48.48]) by port4.iol.cz with ESMTP; 17 Jun 2009 16:31:14 +0200 Message-ID: <4A38FE29.5030205@pjmodos.net> Date: Wed, 17 Jun 2009 16:31:05 +0200 From: Petr Jelinek User-Agent: Thunderbird 2.0.0.21 (Windows/20090302) MIME-Version: 1.0 To: Peter Eisentraut CC: pgsql-hackers@postgresql.org Subject: Re: GRANT ON ALL IN schema References: <4A37BF63.50008@pjmodos.net> <4A37E122.8070303@pjmodos.net> <4A38A956.8080600@pjmodos.net> <200906171644.53717.peter_e@gmx.net> In-Reply-To: <200906171644.53717.peter_e@gmx.net> Content-Type: text/plain; charset=ISO-8859-15; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=0 tagged_above=0 required=5 tests=AWL=0.000 X-Spam-Level: X-Archive-Number: 200906/1061 X-Sequence-Number: 140116 Peter Eisentraut wrote: > I think you should design this with a bit wider scope. Instead of just "all > tables in this schema", think "all tables satisfying some condition". It has > been requested, for example, to be able to grant on all tables that match a > pattern. > Well, that's certainly possible to do. But I am not sure what kind of conditions (besides the name), nor I don't see any sane grammar for this (maybe something like GRANT SELECT ON TABLE WHERE NAME LIKE '%foo' but that's far to weird). That all tables in this schema thing was agreed on on this mailing list and put on TODO so I thought it's something people want in this form (I know I needed it myself). > As far as GRANT is concerned, a view is a table, so I would omit the > VIEW/VIEWS stuff completely. > This maybe true for underlying implementation and for granting permissions to a single object, but you might want to grant select on all views without granting it to all tables in the schema. And as I said having VIEWS and not VIEW just seems weird. Also I don't see why you would want to add possibility of specifying stricter conditions for objects and at the same time remove possibility of distinguishing between tables and views. -- Regards Petr Jelinek (PJMODOS)