Re: [HACKERS] Here it is - view permissions] - Mailing list pgsql-hackers

From Bruce Momjian
Subject Re: [HACKERS] Here it is - view permissions]
Date
Msg-id 199802231315.IAA20853@candle.pha.pa.us
Whole thread Raw
In response to Re: [HACKERS] Here it is - view permissions  (The Hermit Hacker <scrappy@hub.org>)
Responses Re: [HACKERS] Here it is - view permissions]  (The Hermit Hacker <scrappy@hub.org>)
List pgsql-hackers
> > Why does views default to 'select' permission for 'public'?
> > I think most people will never think of the possibility that others
> > will be able to SELECT their data through views.
> > Should not 'create view' at least print a NOTICE about this?
>
>     Considering how much security we are putting around everything
> else, is it unreasonably to have both 'create view'/'create table' default
> to 'revoke all' to public, and 'grant all' to owner?

Most commercial databases don't do this.

--
Bruce Momjian
maillist@candle.pha.pa.us

pgsql-hackers by date:

Previous
From: Andrew Martin
Date:
Subject: Re: [HACKERS] libpgtcl undefined symbol error with pgaccess-0.76
Next
From: jwieck@debis.com (Jan Wieck)
Date:
Subject: Re: [HACKERS] Here it is - view permissions