Re: Restricted access on DataBases

Поиск
Список
Период
Сортировка
От Durumdara
Тема Re: Restricted access on DataBases
Дата
Msg-id CAEcMXhkoEzcDGj9HpRKOBu6E_T8FnepCDrfX5nXdV2RZu+axLw@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Restricted access on DataBases  (Charles Clavadetscher <clavadetscher@swisspug.org>)
Ответы Re: Restricted access on DataBases  (Adrian Klaver <adrian.klaver@aklaver.com>)
Re: Restricted access on DataBases  (Adrian Klaver <adrian.klaver@aklaver.com>)
Список pgsql-general
Dear Charles!

I checked your solution. For example:
db - database
dbuser, mainuser

1. dbuser own the database, and the objects in it.
2. mainuser member of dbuser.
3. public connection revoked.

Ok.

Then dbuser can see all tables, and mainuser too.

Ok.

The operation (overlord):
1. set role to mainuser (or login).
2. create table test_mainuser(id integer);
3. set role to dbuser (or login).
4. select * from test_mainuser;

Result: Permission denied.

Hmmm... the owner of test_mainuser is mainuser...

Then I dropped the test_mainuser table.

I tried to use default privileges. They are for future, so they must be affected on newly created table.
I set them all.


ALTER DEFAULT PRIVILEGES  GRANT INSERT, SELECT, UPDATE, DELETE, TRUNCATE, REFERENCES, TRIGGER ON TABLES to dbuser;

I thought this makes all rights to the newly generated table.

I do the test again, but I got same result.

Why? What I do wrong? (Maybe only my mistake).

I thought before this test that mainuser get all rights as dbuser, so it have rights to the next (future) objects too.
So mainuser and dbuser have equivalent rights in db database.

Thanks for your every info!

Regards
dd








В списке pgsql-general по дате отправления:

Предыдущее
От: Oleg Ivanov
Дата:
Сообщение: Re: Predicting query runtime
Следующее
От: Adrian Klaver
Дата:
Сообщение: Re: Restricted access on DataBases