pg.ddx.io  pgsql-sql@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Mark Stosberg <mark@summersault.com>
To: pgsql-sql@postgresql.org
Subject: Re: Need help revoking access WHERE state = 'deleted'
Date: Thu, 28 Feb 2013 14:29:15 -0500
Message-ID: <512FB00B.7000706@summersault.com> (raw)
In-Reply-To: <9963.1362078492@sss.pgh.pa.us>
References: <kgo14h$vm3$1@ger.gmane.org>
	<20130228180201.GA10412@anubis.morrow.me.uk>
	<kgo811$9al$1@ger.gmane.org>
	<9963.1362078492@sss.pgh.pa.us>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>

On 02/28/2013 02:08 PM, Tom Lane wrote:
> Mark Stosberg <mark@summersault.com> writes:
>> # Explicitly grant access to the view.
>> db=> grant select on entities_not_deleted to myuser;
>> GRANT
> 
>> # Try again to use the view. Still fails
>> db=> SELECT 1 FROM entities_not_deleted WHERE some_col = 'y';
>> ERROR:  permission denied for relation entities
> 
> What's failing is that the *owner of the view* needs, and hasn't got,
> select access on the entities table.  This is a separate check from
> whether the current user has permission to select from the view.
> Without such a check, views would be a security hole.

This was precisely our issue. Thanks, Tom.

I changed the owner of the view, and our approach is working now.

   Mark



-- 
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql



view thread (7+ messages)  latest in thread

Message-ID: <512FB00B.7000706@summersault.com>
Permalink:  ../512FB00B.7000706@summersault.com/
Also on:    postgresql.org/message-id/512FB00B.7000706@summersault.com

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-sql@postgresql.org
  Cc: mark@summersault.com
  Subject: Re: Need help revoking access WHERE state = 'deleted'
  In-Reply-To: <512FB00B.7000706@summersault.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox