Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id 573AE64205E for ; Fri, 7 Aug 2009 23:24:40 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 36994-10 for ; Sat, 8 Aug 2009 02:24:20 +0000 (UTC) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from phoenix.advel.cz (phoenix.advel.cz [81.0.239.26]) by mail.postgresql.org (Postfix) with SMTP id 0D00263F1CC for ; Fri, 7 Aug 2009 23:24:28 -0300 (ADT) Received: (qmail 19290 invoked from network); 8 Aug 2009 04:17:10 +0200 Received: from unknown (HELO ?10.12.0.96?) (88.103.48.48) by 192.168.1.50 with SMTP; 8 Aug 2009 04:17:10 +0200 Message-ID: <4A7CE01D.7060604@pjmodos.net> Date: Sat, 08 Aug 2009 04:17:01 +0200 From: Petr Jelinek User-Agent: Thunderbird 2.0.0.22 (Windows/20090605) MIME-Version: 1.0 To: Stephen Frost CC: Andrew Dunstan , Tom Lane , Robert Haas , Nikhil Sontakke , PostgreSQL-development Subject: Re: GRANT ON ALL IN schema References: <4A38A956.8080600@pjmodos.net> <4A4DE104.8090605@pjmodos.net> <4A6059B4.5010004@pjmodos.net> <4A607997.3030305@pjmodos.net> <603c8f070907191628r6929055coe7627726a33ed143@mail.gmail.com> <603c8f070908050932m19e7db65u9dab6d8001c5a237@mail.gmail.com> <20810.1249490458@sss.pgh.pa.us> <4A79B7E5.1020509@dunslane.net> <20090806152039.GO23840@tamriel.snowman.net> <4A7C77B9.1050008@pjmodos.net> In-Reply-To: <4A7C77B9.1050008@pjmodos.net> Content-Type: text/plain; charset=windows-1250; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=-0.968 tagged_above=-10 required=5 tests=AWL=1.631, BAYES_00=-2.599 X-Spam-Level: X-Archive-Number: 200908/619 X-Sequence-Number: 143262 I am sorry I forgot to write my opinion on these. > Do we want to differentiate views from tables in these commands or not ? I'd like to have views separate but I don't feel strongly about it. However having single statement for TABLE, VIEW and SEQUENCE is not a good idea IMHO, it will add confusion with standard GRANT statement and I don't think we could call it a TABLE anymore. > Do we want GRANT ON ALL (or GRANT ON * which is mysql style, btw) in > SQL form (not functions or client enhancements) at all ? - if we > decide that we don't want to have this as SQL statement then I'll drop > the effort. Well, since I've written the patch I am for it :) Probably with that GRANT ON * and GRANT ON schema.* as it has indeed very low probability that something like that will be in standard with different meaning and also it's mysql compatible (which is the only db currently having this feature I think), even if that's very little plus. Adding the possibility of running commands on many objects at once in psql would be nice addition in the future, especially since we could have more wild syntax there, but I still feel strongly about having the simplest case handled by SQL. > And how do we want to filter default acls ? My opinion is that the best way to do this would be ALTER DEFAULT PRIVILEGES GRANT ..., without any additional filters, it would just affect the role which runs this command. I think this is best solution because ALTER SCHEMA forces creation of many schemas that might not have anything to do with structure of the database (if you want different default privileges for different things). Also having default privileges per role with filters on various things will IMHO create more confusion than good. And finally if somebody wants to have different default privileges for different things than he can just create child roles with different default privileges and use SET SESSION AUTHORIZATION to switch between them. -- Regards Petr Jelinek (PJMODOS)