From: Mark Stosberg <mark@summersault.com>
To: pgsql-sql@postgresql.org
Subject: Re: Need help revoking access WHERE state = 'deleted'
Date: Thu, 28 Feb 2013 14:29:15 -0500
Message-ID: <512FB00B.7000706@summersault.com> (raw)
In-Reply-To: <9963.1362078492@sss.pgh.pa.us>
References: <kgo14h$vm3$1@ger.gmane.org>
<20130228180201.GA10412@anubis.morrow.me.uk>
<kgo811$9al$1@ger.gmane.org>
<9963.1362078492@sss.pgh.pa.us>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>
On 02/28/2013 02:08 PM, Tom Lane wrote:
> Mark Stosberg <mark@summersault.com> writes:
>> # Explicitly grant access to the view.
>> db=> grant select on entities_not_deleted to myuser;
>> GRANT
>
>> # Try again to use the view. Still fails
>> db=> SELECT 1 FROM entities_not_deleted WHERE some_col = 'y';
>> ERROR: permission denied for relation entities
>
> What's failing is that the *owner of the view* needs, and hasn't got,
> select access on the entities table. This is a separate check from
> whether the current user has permission to select from the view.
> Without such a check, views would be a security hole.
This was precisely our issue. Thanks, Tom.
I changed the owner of the view, and our approach is working now.
Mark
--
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-sql@postgresql.org
Cc: mark@summersault.com
Subject: Re: Need help revoking access WHERE state = 'deleted'
In-Reply-To: <512FB00B.7000706@summersault.com>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox