Re: Something I don't understand with the use of schemas

From: Alvaro Herrera <alvherre(at)commandprompt(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Guillaume LELARGE <guillaume(dot)lelarge(at)gmail(dot)com>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: Something I don't understand with the use of schemas
Date: 2005-12-10 17:24:54
Message-ID: 20051210172453.GD3856@surnet.cl
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Tom Lane wrote:
> Alvaro Herrera <alvherre(at)commandprompt(dot)com> writes:
> > However there is an effort to get rid of root in some Unix lands,
> > separating its responsabilities with more granularity. Maybe there
> > could be an effort, not to hand-hold the true superusers, but to
> > delegate some of its responsabilities to other users.
>
> We did that already (see CREATEROLE privilege in 8.1)

Part of it. We can still improve, I think. Not that I have a concrete
proposal to make though.

Regarding CREATEROLE, I wonder why is that a role with that privilege is
able to create other roles containing any privileges (except
superuserness), and not just the privileges the creating role has.

--
Alvaro Herrera http://www.CommandPrompt.com/
PostgreSQL Replication, Consulting, Custom Development, 24x7 support

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Alvaro Herrera 2005-12-10 17:25:46 Re: Something I don't understand with the use of schemas
Previous Message Joshua D. Drake 2005-12-10 17:18:32 Re: Something I don't understand with the use of schemas