Re: bug in permission handling? - Mailing list pgsql-hackers

From Martin Renters
Subject Re: bug in permission handling?
Date
Msg-id 20020114111248.A11077@aspen.datafax.com
Whole thread Raw
In response to Re: bug in permission handling?  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
On Mon, Jan 14, 2002 at 10:29:01AM -0500, Tom Lane wrote:
> Martin Renters <martin@datafax.com> writes:
> > Should the permissions of a deleted user get assigned to a new user
> > as in the example below?
> 
> That can happen, since the default "usesysid" assignment is "max
> existing usesysid + 1".  If you delete the last user then their sysid
> becomes a candidate for reassignment.  This is not real good, but fixing
> it isn't that high on the priority list (and is difficult to do unless
> we take away the option of hand-assigned sysids ... otherwise we could
> just have a sequence generator for sysids).

Isn't it possible for PostgreSQL to delete permissions on tables when a
user gets deleted?  It seems to be a bit of a security issue when a new
user suddenly inherits permissions he shouldn't have.

Martin


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: bug in permission handling?
Next
From: Alex Avriette
Date:
Subject: Re: 7.1 vs. 7.2 on AIX 5L