From: Tom Lane <tgl@sss.pgh.pa.us>
To: Simon Riggs <simon@2ndQuadrant.com>
Cc: Petr Jelinek <pjmodos@pjmodos.net>
Cc: PostgreSQL-development <pgsql-hackers@postgresql.org>
Subject: Re: GRANT ON ALL IN schema
Date: Tue, 07 Jul 2009 11:16:35 -0400
Message-ID: <7045.1246979795@sss.pgh.pa.us> (raw)
In-Reply-To: <1246963514.3874.156.camel@ebony.2ndQuadrant>
References: <4A37BF63.50008@pjmodos.net>
<4A37E122.8070303@pjmodos.net>
<4A38A956.8080600@pjmodos.net>
<4A4DE104.8090605@pjmodos.net>
<1246963514.3874.156.camel@ebony.2ndQuadrant>
Simon Riggs <simon@2ndQuadrant.com> writes:
> I would like to see
> GRANT ... ON ALL OBJECTS ...
This seems inherently broken, since different types of objects
will have different grantable privileges.
> (I'm sure we can do something intelligent with privileges that don't
> apply to all object types rather than just fail. e.g. UPDATE privilege
> should be same as USAGE on a sequence.)
Anything you do in that line will be an ugly kluge, and will tend to
encourage insecure over-granting of privileges (ie GRANT ALL ON ALL
OBJECTS ... what's the point of using permissions at all then?)
regards, tom lane
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-hackers@postgresql.org
Cc: tgl@sss.pgh.pa.us, simon@2ndQuadrant.com, pjmodos@pjmodos.net
Subject: Re: GRANT ON ALL IN schema
In-Reply-To: <7045.1246979795@sss.pgh.pa.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox