Re: Help with privilages please

Поиск
Список
Период
Сортировка
Искать

Re: Help with privilages please

От:
Tom Lane <tgl@sss.pgh.pa.us>
Дата:
Hilary Forbes  writes:
> I have an existing table suppliers and I have created a new user
> 'hilary'

> REVOKE ALL on TABLE suppliers FROM hilary;

> now login as hilary
> SELECT * from suppliers;
> and I get all the records!!!

Most likely there's been a grant of (at least) select privilege to PUBLIC. You'll need to revoke that if you don't want every user to have that privilege implicitly. regards, tom lane

Re: Help with privilages please

От:
"Andrew Hammond" <andrew.george.hammond@gmail.com>
Дата:
7.4.1 is quite old and has a number of serious known bugs. I'd suggest
you either upgrade to 8.1.4 (current) or, if you can't do that, at
least upgrade to 7.4.13 (latest 7.4) immediately.


Hilary Forbes wrote:
> Tom
>
>  Thank you - I think that the underlying problem is that I was trying out
>
>  REVOKE ALL FROM TABLE suppliers FOR public;
>
>  then connect as hilary and I can still see the table rows.
>
>  I appear to have to revoke each type eg
>  REVOKE SELECT FROM TABLE suppliers FOR public;
>  etc and then the code works.
>
>  Is this a known bug in this version (7.4.1)?
>
>  Thanks
>  Hilary
>
>
>  At 18:08 20/07/2006 -0400, Tom Lane wrote:
>
>  Hilary Forbes  writes:
>  > I have an existing table suppliers and I have created a new user
>  > 'hilary'

> > REVOKE ALL on TABLE suppliers FROM hilary;

> > now login as hilary
> > SELECT * from suppliers;
> > and I get all the records!!!

> > Most likely there's been a grant of (at least) select privilege to PUBLIC. > You'll need to revoke that if you don't want every user to have that > privilege implicitly. > > regards, tom lane > > ---------------------------(end of broadcast)--------------------------- > TIP 6: explain analyze is your friend > > Hilary Forbes > DMR Limited (UK registration 01134804) > A DMR Information and Technology Group company (_www.dmr.co.uk_) > Direct tel 01689 889950 Fax 01689 860330 > DMR is a UK registered trade mark of DMR Limited > **********************************************************

Re: Help with privilages please

От:
Stephan Szabo <sszabo@megazone.bigpanda.com>
Дата:
On Thu, 20 Jul 2006, Hilary Forbes wrote:

> Dear All
>
> We are running pg v 7.4.1 and importantly the database has been
> converted from earlier versions of pg (6.5 I seem to recall).
>
> I have an existing table suppliers and I have created a new user 'hilary'
>
> REVOKE ALL on TABLE suppliers FROM hilary;
>
> now login as hilary
> SELECT * from suppliers;
> and I get all the records!!!

This probably means that "public" also has rights on suppliers (and thus,
the user still has access through the public permissions). You can
probably get around this by revoking the public rights and granting rights
explicitly to the users that should have rights.


Re: Help with privilages please

От:
Richard Broersma Jr <rabroersma@yahoo.com>
Дата:
REVOKE ALL on TABLE suppliers FROM hilary;
now login as hilary
SELECT * from suppliers;
and I get all the records!!!
If I create a **new** table though and then do the above, the permissionswork I get a polite
message telling me "no go".  Thissounds to me like a problem with earlier compatibility.  Is there
away I can overcome this.  A simple dump/restore does not solve theproblem.


You might also have to revoke all from public:

Regards,
Richard Broersma Jr.

Help with privilages please

От:
Hilary Forbes <hforbes@dmr.co.uk>
Дата:
 Dear All

We are running pg v 7.4.1 and importantly the database has been converted from earlier versions of pg (6.5 I seem to recall).

I have an existing table suppliers and I have created a new user 'hilary'

REVOKE ALL on TABLE suppliers FROM hilary;

now login as hilary
SELECT * from suppliers;
and I get all the records!!!

If I create a **new** table though and then do the above, the permissions work I get a polite message telling me "no go".  This sounds to me like a problem with earlier compatibility.  Is there a way I can overcome this.  A simple dump/restore does not solve the problem.

Many thanks
Hilary

Hilary Forbes
DMR Limited (UK registration 01134804)
A DMR Information and Technology Group company (www.dmr.co.uk)
Direct tel 01689 889950 Fax 01689 860330
DMR is a UK registered trade mark of DMR Limited
**********************************************************

Re: Help with privilages please

От:
Hilary Forbes <hforbes@dmr.co.uk>
Дата:
 Tom

Thank you - I think that the underlying problem is that I was trying out

REVOKE ALL FROM TABLE suppliers FOR public;

then connect as hilary and I can still see the table rows.

I appear to have to revoke each type eg
REVOKE SELECT FROM TABLE suppliers FOR public;
etc and then the code works.

Is this a known bug in this version (7.4.1)?

Thanks
Hilary


At 18:08 20/07/2006 -0400, Tom Lane wrote:

Hilary Forbes <hforbes@dmr.co.uk> writes:
> I have an existing table suppliers and I have created a new user
> 'hilary'<br><br>
> REVOKE ALL on TABLE suppliers FROM hilary;<br><br>
> now login as hilary<br>
> SELECT * from suppliers;<br>
> and I get all the records!!!<br><br>

Most likely there's been a grant of (at least) select privilege to PUBLIC.
You'll need to revoke that if you don't want every user to have that
privilege implicitly.

                        regards, tom lane

---------------------------(end of broadcast)---------------------------
TIP 6: explain analyze is your friend

Hilary Forbes
DMR Limited (UK registration 01134804)
A DMR Information and Technology Group company (www.dmr.co.uk)
Direct tel 01689 889950 Fax 01689 860330
DMR is a UK registered trade mark of DMR Limited
**********************************************************

FAQ