Re: Please advice TODO Item pg_hba.conf

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: Please advice TODO Item pg_hba.conf
Дата
Msg-id 20060423222820.GG4775@surnet.cl
обсуждение исходный текст
Ответ на Re: Please advice TODO Item pg_hba.conf  (Gevik Babakhani <pgdev@xs4all.nl>)
Ответы Re: Please advice TODO Item pg_hba.conf  (Gevik Babakhani <pgdev@xs4all.nl>)
Re: Please advice TODO Item pg_hba.conf  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Gevik Babakhani wrote:

> > > Personally I think it would be better for the database owner not have
> > > the option to REVOKE himself from the CONNECTION privilege of his own
> > > database. 
> > 
> > Why?  A table owner can revoke privileges from himself.
> 
> Of course a TABLE owner can revoke privileges from himself. But why
> would a DATABASE owner want to lock himself out from CONNECTING to his
> database.

I don't know :-)  If it doesn't make sense for somebody, then she won't
do it.

It's not like we are going out of our way to allow somebody to revoke
the privileges from oneself.  We are just keeping the thing as simple as
possible.  As I said, maybe a reasonable option would be to raise a
WARNING when somebody revoked the last CONNECT privilege.  So you grant
the privilege to somebody else and the revoke yours.

> Perhaps there is a legitimate reason for this but it doesn't
> make sense. Right? I see it this way: Why should I lockout myself from
> my own house and throw the keys away. (I am a man of simple words and
> examples, I must apologize.)

Maybe you've given a copy of the keys to somebody else.

-- 
Alvaro Herrera                                http://www.CommandPrompt.com/
PostgreSQL Replication, Consulting, Custom Development, 24x7 support


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Jonah H. Harris"
Дата:
Сообщение: Re: Google SoC--Idea Request
Следующее
От: Alvaro Herrera
Дата:
Сообщение: Re: Question about dependency functions in the backend