Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB8q0-0000Zo-56 for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 19:08:16 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.72) (envelope-from ) id 1UB8pz-0007tf-JU for pgsql-sql@arkaria.postgresql.org; Thu, 28 Feb 2013 19:08:15 +0000 Received: from makus.postgresql.org ([2001:4800:7903:4::125]) by malur.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB8py-0007se-8G for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 19:08:14 +0000 Received: from sss.pgh.pa.us ([66.207.139.130]) by makus.postgresql.org with esmtp (Exim 4.72) (envelope-from ) id 1UB8px-0005d0-4g for pgsql-sql@postgresql.org; Thu, 28 Feb 2013 19:08:13 +0000 Received: from sss2.sss.pgh.pa.us (tgl@localhost [127.0.0.1]) by sss.pgh.pa.us (8.14.5/8.14.5) with ESMTP id r1SJ8CSm009964; Thu, 28 Feb 2013 14:08:12 -0500 (EST) From: Tom Lane To: Mark Stosberg cc: pgsql-sql@postgresql.org Subject: Re: Need help revoking access WHERE state = 'deleted' In-reply-to: References: <20130228180201.GA10412@anubis.morrow.me.uk> Comments: In-reply-to Mark Stosberg message dated "Thu, 28 Feb 2013 13:35:15 -0500" Date: Thu, 28 Feb 2013 14:08:12 -0500 Message-ID: <9963.1362078492@sss.pgh.pa.us> X-Pg-Spam-Score: -2.6 (--) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-sql Precedence: bulk Sender: pgsql-sql-owner@postgresql.org Mark Stosberg writes: > # Explicitly grant access to the view. > db=> grant select on entities_not_deleted to myuser; > GRANT > # Try again to use the view. Still fails > db=> SELECT 1 FROM entities_not_deleted WHERE some_col = 'y'; > ERROR: permission denied for relation entities What's failing is that the *owner of the view* needs, and hasn't got, select access on the entities table. This is a separate check from whether the current user has permission to select from the view. Without such a check, views would be a security hole. regards, tom lane -- Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-sql