agora inbox for pgsql-sql@postgresql.org  
help / color / mirror / Atom feed
From: Karsten Hilbert <Karsten.Hilbert@gmx.net>
To: pgsql-sql@postgresql.org
Subject: Re: simple "select / if found" isn't
Date: Fri, 16 Dec 2016 12:12:13 +0100
Message-ID: <20161216111212.edknff56d52bgrjl@hermes.hilbert.loc> (raw)
In-Reply-To: <201612161102.37559.gary.stainburn@ringways.co.uk>
References: <201612161102.37559.gary.stainburn@ringways.co.uk>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>

On Fri, Dec 16, 2016 at 11:02:37AM +0000, Gary Stainburn wrote:

> All I want to do is return 'found' based on the select but I can't get it to 
> work.  
> 
> If I run 
> 
> select 1 from user_previous_passwords 
> 	where u_id=25 and 
> 	crypt('MyPaSSword',u_previous_password) = u_previous_password;
> 
> then it returns the matching row(s)
> 
> If I run my function
> 
> create or replace function check_previous_passwords (ID int4, PASS varchar) 
> returns boolean as $$

It just _might_ have to do with permissions to
user_previous_passwords.

If the function somehow got installed as "security definer"
and definer does not have RLS-based (!) permissions on
user_previous_passwords then it won't find rows.

A shot in the dark...

Karsten
-- 
GPG key ID E4071346 @ eu.pool.sks-keyservers.net
E167 67FD A291 2BEA 73BD  4537 78B9 A9F9 E407 1346


-- 
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql



view thread (6+ messages)  latest in thread

Message-ID: <20161216111212.edknff56d52bgrjl@hermes.hilbert.loc>
Permalink:  ../20161216111212.edknff56d52bgrjl@hermes.hilbert.loc/
Also on:    postgresql.org/message-id/20161216111212.edknff56d52bgrjl@hermes.hilbert.loc

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-sql@postgresql.org
  Cc: Karsten.Hilbert@gmx.net
  Subject: Re: simple "select / if found" isn't
  In-Reply-To: <20161216111212.edknff56d52bgrjl@hermes.hilbert.loc>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox