Received: from localhost (unknown [200.46.208.211]) by mail.postgresql.org (Postfix) with ESMTP id DD109632CED for ; Tue, 7 Jul 2009 12:16:55 -0300 (ADT) Received: from mail.postgresql.org ([200.46.204.86]) by localhost (mx1.hub.org [200.46.208.211]) (amavisd-maia, port 10024) with ESMTP id 27828-04 for ; Tue, 7 Jul 2009 12:16:44 -0300 (ADT) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from sss.pgh.pa.us (sss.pgh.pa.us [66.207.139.130]) by mail.postgresql.org (Postfix) with ESMTP id 6A14763391E for ; Tue, 7 Jul 2009 12:16:40 -0300 (ADT) Received: from sss2.sss.pgh.pa.us (tgl@localhost [127.0.0.1]) by sss.pgh.pa.us (8.14.2/8.14.2) with ESMTP id n67FGZLt007046; Tue, 7 Jul 2009 11:16:35 -0400 (EDT) To: Simon Riggs cc: Petr Jelinek , PostgreSQL-development Subject: Re: GRANT ON ALL IN schema In-reply-to: <1246963514.3874.156.camel@ebony.2ndQuadrant> References: <4A37BF63.50008@pjmodos.net> <4A37E122.8070303@pjmodos.net> <4A38A956.8080600@pjmodos.net> <4A4DE104.8090605@pjmodos.net> <1246963514.3874.156.camel@ebony.2ndQuadrant> Comments: In-reply-to Simon Riggs message dated "Tue, 07 Jul 2009 11:45:14 +0100" Date: Tue, 07 Jul 2009 11:16:35 -0400 Message-ID: <7045.1246979795@sss.pgh.pa.us> From: Tom Lane X-Virus-Scanned: Maia Mailguard 1.0.1 X-Spam-Status: No, hits=0.083 tagged_above=0 required=5 tests=AWL=0.083 X-Spam-Level: X-Archive-Number: 200907/387 X-Sequence-Number: 141009 Simon Riggs writes: > I would like to see > GRANT ... ON ALL OBJECTS ... This seems inherently broken, since different types of objects will have different grantable privileges. > (I'm sure we can do something intelligent with privileges that don't > apply to all object types rather than just fail. e.g. UPDATE privilege > should be same as USAGE on a sequence.) Anything you do in that line will be an ugly kluge, and will tend to encourage insecure over-granting of privileges (ie GRANT ALL ON ALL OBJECTS ... what's the point of using permissions at all then?) regards, tom lane