From: Tom Lane <tgl@sss.pgh.pa.us>
To: Mark Stosberg <mark@summersault.com>
Cc: pgsql-sql@postgresql.org
Subject: Re: Need help revoking access WHERE state = 'deleted'
Date: Thu, 28 Feb 2013 14:08:12 -0500
Message-ID: <9963.1362078492@sss.pgh.pa.us> (raw)
In-Reply-To: <kgo811$9al$1@ger.gmane.org>
References: <kgo14h$vm3$1@ger.gmane.org>
<20130228180201.GA10412@anubis.morrow.me.uk>
<kgo811$9al$1@ger.gmane.org>
List-Unsubscribe: <mailto:majordomo@postgresql.org?body=unsub%20pgsql-sql>
Mark Stosberg <mark@summersault.com> writes:
> # Explicitly grant access to the view.
> db=> grant select on entities_not_deleted to myuser;
> GRANT
> # Try again to use the view. Still fails
> db=> SELECT 1 FROM entities_not_deleted WHERE some_col = 'y';
> ERROR: permission denied for relation entities
What's failing is that the *owner of the view* needs, and hasn't got,
select access on the entities table. This is a separate check from
whether the current user has permission to select from the view.
Without such a check, views would be a security hole.
regards, tom lane
--
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-sql@postgresql.org
Cc: tgl@sss.pgh.pa.us, mark@summersault.com
Subject: Re: Need help revoking access WHERE state = 'deleted'
In-Reply-To: <9963.1362078492@sss.pgh.pa.us>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox