Re: Permissions not working

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Pallav Kalva <pkalva(at)deg(dot)cc>
Cc: "scott(dot)marlowe" <scott(dot)marlowe(at)ihs(dot)com>, pgsql-sql(at)postgresql(dot)org
Subject: Re: Permissions not working
Date: 2004-04-30 16:19:39
Message-ID: 26201.1083341979@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-sql

Pallav Kalva <pkalva(at)deg(dot)cc> writes:
> usps=> \z citystate_alias
> Access privileges
> for database "usps"
> Schema | Table
> | Access privileges
> --------+-----------------+-----------------------------------------------------------------------------------------------------------------------
> public | citystate_alias |
> {postgres=a*r*w*d*R*x*t*/postgres,=r/postgres,usps=arwdRxt/postgres,"group
> 100=r/usps","group ea_development=r/usps"}
> (1 row)

It looks to me like (a) this table is owned by postgres not usps, and
(b) postgres has granted SELECT permission to PUBLIC (that's what the
"=r/postgres" part means). The usps user isn't going to be able to
revoke that because he doesn't own the table.

It does seem like you've found a bug of some kind though: the above
shows that user usps does not have GRANT OPTION rights of any kind
(there are no stars in his privilege list). So how was he able to grant
SELECT rights to those two groups? Do you have the exact sequence of
GRANT and REVOKE operations that were performed on this table? What
PG version is this, exactly?

regards, tom lane

In response to

Responses

Browse pgsql-sql by date

  From Date Subject
Next Message Frank Bax 2004-04-30 16:24:03 Re: isnumeric() function?
Previous Message Yudie 2004-04-30 15:29:16 Re: isnumeric() function?