Re: dropdb ; createdb equivalent without createdb permission? - Mailing list pgsql-general

From Tom Lane
Subject Re: dropdb ; createdb equivalent without createdb permission?
Date
Msg-id 25426.1184007002@sss.pgh.pa.us
Whole thread Raw
In response to Re: dropdb ; createdb equivalent without createdb permission?  (Andrew Sullivan <ajs@crankycanuck.ca>)
Responses Re: dropdb ; createdb equivalent without createdb permission?
List pgsql-general
Andrew Sullivan <ajs@crankycanuck.ca> writes:
> On Mon, Jul 09, 2007 at 02:13:55PM -0400, Tim Olsen wrote:
>> like the user to be granted createdb permission for only a particular
>> database.  I don't believe this is possible in postgresql.  Is there a
>> dropdb-followed-by-createdb equivalent the user could use?

> You could, however, limit all of this by giving sudo access to the
> person in question, where the sudo access is for a (set of) script(s)
> that achieve what you want (e.g. scripts with the appropriate
> createdb, psql -c "something" &c. inside them).

A SECURITY DEFINER function (living in some other database of course)
could accomplish this without going outside Postgres.

            regards, tom lane

pgsql-general by date:

Previous
From: "Tim Olsen"
Date:
Subject: Re: dropdb ; createdb equivalent without createdb permission?
Next
From: Andrew Sullivan
Date:
Subject: Re: dropdb ; createdb equivalent without createdb permission?