Re: Regarding TODO item "%Add a separate TRUNCATE - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: Regarding TODO item "%Add a separate TRUNCATE
Date
Msg-id 20060426175728.GO4474@ns.snowman.net
Whole thread Raw
In response to Re: Regarding TODO item "%Add a separate TRUNCATE  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
* Tom Lane (tgl@sss.pgh.pa.us) wrote:
> Gevik Babakhani <pgdev@xs4all.nl> writes:
> > Would the privilege apply to the table depending on the table being
> > truncated?
>
> I think the idea is to require TRUNCATE privilege on all the tables
> being truncated in the command.  This would substitute for the existing
> ownership check.

Right, definitely agree about this.

> I do have a concern here, which is that GRANT ALL on a table didn't use
> to convey TRUNCATE, but now it will.  However, since GRANT ALL does
> confer the right to do "DELETE FROM tab", maybe this isn't an issue.

Hmmm, I have to agree that this an interesting question.  I don't tend
to use "GRANT ALL" so I'm not really sure what people are thinking when
they use it.  It seems to me that it'd make sense to include TRUNCATE in
'GRANT ALL' (since it includes the abilities to create triggers and
references, etc, which I wouldn't generally consider to be "normal",
where "normal" would be select/insert/update/delete).
Thanks,
    Stephen

pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Regarding TODO item "%Add a separate TRUNCATE permission"
Next
From: Stephen Frost
Date:
Subject: Re: Regarding TODO item "%Add a separate TRUNCATE permission"