Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id 52A156326C7 for ; Wed, 5 Aug 2009 13:53:18 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 34875-01-4 for ; Wed, 5 Aug 2009 16:53:06 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-fx0-f220.google.com (mail-fx0-f220.google.com [209.85.220.220]) by mail.postgresql.org (Postfix) with ESMTP id F39EC635E74 for ; Wed, 5 Aug 2009 13:51:42 -0300 (ADT) Received: by fxm20 with SMTP id 20so227353fxm.24 for ; Wed, 05 Aug 2009 09:51:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=VuKWRzZr+b6h8YJJJKct61Y8ZQQxCStAbkFhuntSPr8=; b=HSiGTWtqK1yhXSRVl26kJBoO19OSxhE8PDLNBorObe2FFiX1gQLacdZ3+y+gQxnMQV qeP+mrczEqOkEUfvjBUHkTX7YaDxXUFcfSSwfwW1Mv1j85iLfc/S3GzqWD6mH/dqA9yS YTUX7Sb4XXK1fv7zaeHsiPjG0USpHID4qwT7M= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; b=qDUuL4E4dpHxtTslm3fnnIm4vR3nrWcbobUSa/VXKaTG92gygCqVgmLTgxbnZlhrKe aa9OdKhJvL/tiZIIb244ZJDA5hPvyXEhKdMbG7ZmOo8bC30JbVcn1vpuhZlVG0lXblP4 mYY7FagfFeWTgWfBBvUZ6txoUwtcXKtMq5/VM= MIME-Version: 1.0 Received: by 10.223.120.67 with SMTP id c3mr3788727far.15.1249491101471; Wed, 05 Aug 2009 09:51:41 -0700 (PDT) In-Reply-To: <20810.1249490458@sss.pgh.pa.us> References: <4A37BF63.50008@pjmodos.net> <4A38A956.8080600@pjmodos.net> <4A4DE104.8090605@pjmodos.net> <4A6059B4.5010004@pjmodos.net> <4A607997.3030305@pjmodos.net> <603c8f070907191628r6929055coe7627726a33ed143@mail.gmail.com> <603c8f070908050932m19e7db65u9dab6d8001c5a237@mail.gmail.com> <20810.1249490458@sss.pgh.pa.us> Date: Wed, 5 Aug 2009 12:51:41 -0400 Message-ID: <603c8f070908050951s3e5df452se4c610f01b80bb7d@mail.gmail.com> Subject: Re: GRANT ON ALL IN schema From: Robert Haas To: Tom Lane Cc: Stephen Frost , Nikhil Sontakke , Petr Jelinek , PostgreSQL-development Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=-1.322 tagged_above=-10 required=5 tests=AWL=1.277, BAYES_00=-2.599 X-Spam-Level: X-Archive-Number: 200908/333 X-Sequence-Number: 142976 On Wed, Aug 5, 2009 at 12:40 PM, Tom Lane wrote: > Robert Haas writes: >> My understanding is that this patch will need to be reworked as well >> based on Tom's comments on "DefaultACLs". =A0Does that sound right? >> Should we expect a new version this week, or defer this until the >> September CommitFest? > > I was planning to go review that patch too, even though it's presumably > not committable yet. OK, that's good information, thanks. > I'm not sure whether there is consensus on not using GRANT ON VIEW > (ie, having these patches treat tables and views alike). =A0I was waiting > to see if Stephen would put forward a convincing counterargument ... The argument is better for defaults that it is for grant on all, I think, though we also don't want the two to be asymmetric. Defaults need to be really simple to have any value, I think, and avoid violating the POLA. But bulk-grant could be based on object type, object name (with wildcard or regexp pattern), schema membership, or maybe other things, and I think that would be quite useful if we can figure out how to make it clean and elegant. ...Robert