Re: [HACKERS] Here it is - view permissions

From: jwieck(at)debis(dot)com (Jan Wieck)
To: maillist(at)candle(dot)pha(dot)pa(dot)us (Bruce Momjian)
Cc: jwieck(at)debis(dot)com, pgsql-hackers(at)postgreSQL(dot)org, pgsql-patches(at)postgreSQL(dot)org
Subject: Re: [HACKERS] Here it is - view permissions
Date: 1998-02-21 11:46:10
Message-ID: m0y6DNi-000BFRC@orion.SAPserv.Hamburg.dsh.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Bruce wrote:
>
> > This flag is useful anyway. We change the world now that ALL
> > views are overriding the acl checks. If we have this flag we
> > can setup views that behave like before (user cannot see
> > anything through the view he cannot see without) and use the
> > overriding only in cases we need it (like for the pg_user
> > permissions problem). I'll work on it.
>
> OK, but why would anyone want the old behavior?
>
> I guess if you have a table that is not select-able by everyone, and you
> create a view on it, the default permits will allow select to others.
> You would have to set the permit on that view. Is there more to that
> pg_class flag you want to add?

No, there isn't more on that. It's just to be more backward
compatible. Users out there might have already views and
since it wasn't neccessary to set explicit permissions on a
view up to now (views inherited the permissions from all
tables they select), it's unlikely that anyone out there set
them up.

I think it's better to implement something that's a key to
open the door instead of opening it by default and telling
where's the key to lock it back.

Jan

--

#======================================================================#
# It's easier to get forgiveness for being wrong than for being right. #
# Let's break this rule - forgive me. #
#======================================== jwieck(at)debis(dot)com (Jan Wieck) #

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Jan Wieck 1998-02-21 11:53:02 Re: [PATCHES] Here it is - view permissions
Previous Message Jan Wieck 1998-02-21 11:34:38 Re: [HACKERS] Permissions on copy