Re: Help with privilages please
Re: Help with privilages please
От:
Tom Lane <tgl@sss.pgh.pa.us>
Дата:
Hilary Forbes writes: > I have an existing table suppliers and I have created a new user > 'hilary'
> REVOKE ALL on TABLE suppliers FROM hilary;
> now login as hilary
> SELECT * from suppliers;
> and I get all the records!!!
Most likely there's been a grant of (at least) select privilege to PUBLIC. You'll need to revoke that if you don't want every user to have that privilege implicitly. regards, tom lane
Re: Help with privilages please
От:
"Andrew Hammond" <andrew.george.hammond@gmail.com>
Дата:
7.4.1 is quite old and has a number of serious known bugs. I'd suggest you either upgrade to 8.1.4 (current) or, if you can't do that, at least upgrade to 7.4.13 (latest 7.4) immediately. Hilary Forbes wrote: > Tom > > Thank you - I think that the underlying problem is that I was trying out > > REVOKE ALL FROM TABLE suppliers FOR public; > > then connect as hilary and I can still see the table rows. > > I appear to have to revoke each type eg > REVOKE SELECT FROM TABLE suppliers FOR public; > etc and then the code works. > > Is this a known bug in this version (7.4.1)? > > Thanks > Hilary > > > At 18:08 20/07/2006 -0400, Tom Lane wrote: > > Hilary Forbes writes: > > I have an existing table suppliers and I have created a new user > > 'hilary'
> > REVOKE ALL on TABLE suppliers FROM hilary;
> > now login as hilary
> > SELECT * from suppliers;
> > and I get all the records!!!
> > Most likely there's been a grant of (at least) select privilege to PUBLIC. > You'll need to revoke that if you don't want every user to have that > privilege implicitly. > > regards, tom lane > > ---------------------------(end of broadcast)--------------------------- > TIP 6: explain analyze is your friend > > Hilary Forbes > DMR Limited (UK registration 01134804) > A DMR Information and Technology Group company (_www.dmr.co.uk_) > Direct tel 01689 889950 Fax 01689 860330 > DMR is a UK registered trade mark of DMR Limited > **********************************************************
Re: Help with privilages please
От:
Stephan Szabo <sszabo@megazone.bigpanda.com>
Дата:
On Thu, 20 Jul 2006, Hilary Forbes wrote: > Dear All > > We are running pg v 7.4.1 and importantly the database has been > converted from earlier versions of pg (6.5 I seem to recall). > > I have an existing table suppliers and I have created a new user 'hilary' > > REVOKE ALL on TABLE suppliers FROM hilary; > > now login as hilary > SELECT * from suppliers; > and I get all the records!!! This probably means that "public" also has rights on suppliers (and thus, the user still has access through the public permissions). You can probably get around this by revoking the public rights and granting rights explicitly to the users that should have rights.
Re: Help with privilages please
От:
Richard Broersma Jr <rabroersma@yahoo.com>
Дата:
REVOKE ALL on TABLE suppliers FROM hilary; now login as hilary SELECT * from suppliers; and I get all the records!!! If I create a **new** table though and then do the above, the permissionswork I get a polite message telling me "no go". Thissounds to me like a problem with earlier compatibility. Is there away I can overcome this. A simple dump/restore does not solve theproblem. You might also have to revoke all from public: Regards, Richard Broersma Jr.
Help with privilages please
От:
Hilary Forbes <hforbes@dmr.co.uk>
Дата:
Dear All
We are running pg v 7.4.1 and importantly the database has been converted from earlier versions of pg (6.5 I seem to recall).
I have an existing table suppliers and I have created a new user 'hilary'
REVOKE ALL on TABLE suppliers FROM hilary;
now login as hilary
SELECT * from suppliers;
and I get all the records!!!
If I create a **new** table though and then do the above, the permissions work I get a polite message telling me "no go". This sounds to me like a problem with earlier compatibility. Is there a way I can overcome this. A simple dump/restore does not solve the problem.
Many thanks
HilaryHilary Forbes
DMR Limited (UK registration 01134804)
A DMR Information and Technology Group company (www.dmr.co.uk)
Direct tel 01689 889950 Fax 01689 860330
DMR is a UK registered trade mark of DMR Limited
**********************************************************
Re: Help with privilages please
От:
Hilary Forbes <hforbes@dmr.co.uk>
Дата:
Tom
Thank you - I think that the underlying problem is that I was trying out
REVOKE ALL FROM TABLE suppliers FOR public;
then connect as hilary and I can still see the table rows.
I appear to have to revoke each type eg
REVOKE SELECT FROM TABLE suppliers FOR public;
etc and then the code works.
Is this a known bug in this version (7.4.1)?
Thanks
Hilary
At 18:08 20/07/2006 -0400, Tom Lane wrote:Hilary Forbes <hforbes@dmr.co.uk> writes:
> I have an existing table suppliers and I have created a new user
> 'hilary'<br><br>
> REVOKE ALL on TABLE suppliers FROM hilary;<br><br>
> now login as hilary<br>
> SELECT * from suppliers;<br>
> and I get all the records!!!<br><br>
Most likely there's been a grant of (at least) select privilege to PUBLIC.
You'll need to revoke that if you don't want every user to have that
privilege implicitly.
regards, tom lane
---------------------------(end of broadcast)---------------------------
TIP 6: explain analyze is your friendHilary Forbes
DMR Limited (UK registration 01134804)
A DMR Information and Technology Group company (www.dmr.co.uk)
Direct tel 01689 889950 Fax 01689 860330
DMR is a UK registered trade mark of DMR Limited
**********************************************************