Re: Additional role attributes && superuser review - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: Additional role attributes && superuser review
Date
Msg-id 20141016193709.GK28859@tamriel.snowman.net
Whole thread Raw
In response to Re: Additional role attributes && superuser review  (Simon Riggs <simon@2ndQuadrant.com>)
Responses Re: Additional role attributes && superuser review
List pgsql-hackers
* Simon Riggs (simon@2ndQuadrant.com) wrote:
> On 16 October 2014 20:04, Robert Haas <robertmhaas@gmail.com> wrote:
> >>> GRANT CAPABILITY whatever TO somebody;
> >>
> >> So, we went back to just role attributes to avoid the keyword issue..
> >> The above would require making 'CAPABILITY' a reserved word, and there
> >> really isn't a 'good' already-reserved word we can use there that I
> >> found.
> >
> > Ah, good point.  Using ALTER ROLE is better.  Maybe we should do ALTER
> > ROLE .. [ ADD | DROP ] CAPABILITY x.  That would still require making
> > CAPABILITY a keyword, but it could be unreserved.
>
> I thought you had it right first time. It is mighty annoying that some
> privileges are GRANTed and others ALTER ROLEd.

Yeah- but there's a material difference in the two, as I tried to
outline previously..

> How about
>
> GRANT EXECUTE [PRIVILEGES] ON CAPABILITY foo TO bar;
>
> That is similar to granting execution privs on a function. And I think
> gets round the keyword issue?

No, it doesn't..  EXECUTE isn't reserved at all.
Thanks,
    Stephen

pgsql-hackers by date:

Previous
From: Simon Riggs
Date:
Subject: Re: Additional role attributes && superuser review
Next
From: "Brightwell, Adam"
Date:
Subject: Re: Review of GetUserId() Usage