Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB9AQ-0002ao-Af for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 19:29:22 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.72) (envelope-from ) id 1UB9AP-0005QU-Q0 for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 19:29:21 +0000 Received: from makus.postgresql.org ([2001:4800:7903:4::125]) by malur.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB9AO-0005P9-FE for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 19:29:20 +0000 Received: from tanagra.summersault.com ([12.161.105.149]) by makus.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB9AM-0005x6-GM for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 19:29:19 +0000 Received: (qmail 1580 invoked from network); 28 Feb 2013 19:29:17 -0000 Received: from simba.summersault.com (HELO ?192.168.97.182?) (192.168.97.182) by tanagra.summersault.com with SMTP; 28 Feb 2013 19:29:17 -0000 Message-ID: <512FB00B.7000706@summersault.com> Date: Thu, 28 Feb 2013 14:29:15 -0500 From: Mark Stosberg User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130221 Thunderbird/17.0.3 MIME-Version: 1.0 To: pgsql-sql@postgresql.org Subject: Re: Need help revoking access WHERE state = 'deleted' References: <20130228180201.GA10412@anubis.morrow.me.uk> <9963.1362078492@sss.pgh.pa.us> In-Reply-To: <9963.1362078492@sss.pgh.pa.us> X-Enigmail-Version: 1.5 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Pg-Spam-Score: -2.6 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-sql Precedence: bulk Sender: pgsql-sql-owner@postgresql.org On 02/28/2013 02:08 PM, Tom Lane wrote: > Mark Stosberg writes: >> # Explicitly grant access to the view. >> db=> grant select on entities_not_deleted to myuser; >> GRANT > >> # Try again to use the view. Still fails >> db=> SELECT 1 FROM entities_not_deleted WHERE some_col = 'y'; >> ERROR: permission denied for relation entities > > What's failing is that the *owner of the view* needs, and hasn't got, > select access on the entities table. This is a separate check from > whether the current user has permission to select from the view. > Without such a check, views would be a security hole. This was precisely our issue. Thanks, Tom. I changed the owner of the view, and our approach is working now. Mark -- Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-sql