Re: TODO item: set proper permissions on non-system schemas - Mailing list pgsql-hackers

From Tom Lane
Subject Re: TODO item: set proper permissions on non-system schemas
Date
Msg-id 12841.1125586863@sss.pgh.pa.us
Whole thread Raw
In response to Re: TODO item: set proper permissions on non-system schemas  (Andrew - Supernews <andrew+nonews@supernews.com>)
Responses Re: TODO item: set proper permissions on non-system schemas
List pgsql-hackers
Andrew - Supernews <andrew+nonews@supernews.com> writes:
> On 2005-09-01, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>> There is some merit in the thought that the DB owner should be able to
>> grant and revoke access on the public schema, but that no longer
>> requires ownership, only membership in an appropriate role.

> How would that work without superuser intervention, given that the
> ownership of public would be the same in all databases regardless of
> who created them?

Change the ownership of public in template1 to be a "dbadmin" group.
Grant membership in "dbadmin" to all the DB owners.  End of problem.
        regards, tom lane


pgsql-hackers by date:

Previous
From: David Fetter
Date:
Subject: Re: broken configure, broken makefile?
Next
From: "William ZHANG"
Date:
Subject: Re: Call for 7.5 feature completion