Re: Clarification on Role Access Rights to Table Indexes

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Clarification on Role Access Rights to Table Indexes
Дата
Msg-id 934709.1739829723@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Clarification on Role Access Rights to Table Indexes  (Ayush Vatsa <ayushvatsa1810@gmail.com>)
Ответы Re: Clarification on Role Access Rights to Table Indexes
Список pgsql-hackers
Ayush Vatsa <ayushvatsa1810@gmail.com> writes:
> Thanks Robert for confirming, let me submit a patch to fix the same.

Well, the first thing you need is consensus on what the behavior
should be instead.

I have a very vague recollection that we concluded that SELECT
privilege was a reasonable check because if you have that you
could manually prewarm by reading the table.  That would lead
to the conclusion that the minimal fix is to look at the owning
table's privileges instead of the index's own privileges.

Or we could switch to using ownership, which'd keep the code
simple but some users might complain it's too restrictive.

While I mentioned built-in roles earlier, I now think those mostly
carry more privilege than should be required here, given the analogy
to SELECT.

            regards, tom lane



В списке pgsql-hackers по дате отправления: