Re: Alter Default Privileges Does Not Work For Functions - Mailing list pgsql-general

From Tom Lane
Subject Re: Alter Default Privileges Does Not Work For Functions
Date
Msg-id 23604.1297728273@sss.pgh.pa.us
Whole thread Raw
In response to Alter Default Privileges Does Not Work For Functions  ("David Johnston" <polobo@yahoo.com>)
Responses Re: Alter Default Privileges Does Not Work For Functions  ("David Johnston" <polobo@yahoo.com>)
List pgsql-general
"David Johnston" <polobo@yahoo.com> writes:
> After creating and logging into a new database run this script.   The
> initial ALTER DEFAULT PRIVILEGES should make all users unable to execute
> functions unless given explicit permissions elsewhere.

You haven't read the fine manual very closely.  It saith

    Default privileges that are specified per-schema are added to
    whatever the global default privileges are for the particular
    object type.

and

    As explained under GRANT, the default privileges for any object
    type normally grant all grantable permissions to the object
    owner, and may grant some privileges to PUBLIC as well. However,
    this behavior can be changed by altering the global default
    privileges with ALTER DEFAULT PRIVILEGES.

If you want to revoke the default execute privileges for functions, you
have to do it globally, ie, not per-schema.  There's no way to reduce
the default privileges at the per-schema level.

            regards, tom lane

pgsql-general by date:

Previous
From: deepak
Date:
Subject: Building extensions on Windows using VS2008
Next
From: Derrick Rice
Date:
Subject: Speeding up index scans by truncating timestamp?