Re: weird problem with grants - Mailing list pgsql-general

From Tom Lane
Subject Re: weird problem with grants
Date
Msg-id 6131.1128980783@sss.pgh.pa.us
Whole thread Raw
In response to weird problem with grants  (Dick Kniep <dick@kniep.nl>)
List pgsql-general
Dick Kniep <dick@kniep.nl> writes:
> We have a user 'x' that is member of group 'a'
> there is a sequence where
> Grant all on table schema.sequence to group 'a'

> But still I get a permission denied when I try to access the sequence as user
> 'x'.

Works fine for me, so you've omitted some critical bit of information.

regression=# create user x;
CREATE ROLE
regression=# create group g with user x;
CREATE ROLE
regression=# create sequence seq;
CREATE SEQUENCE
regression=# grant all on seq to group g;
GRANT
regression=# \c - x
You are now connected as new user "x".
regression=> select nextval('seq');
 nextval
---------
       1
(1 row)

Given that you've mentioned schemas, a couple of possibilities are that
user x doesn't have USAGE permission on the schema containing the
sequence, or that he has a different search path which is leading him
to find a different sequence altogether.

If that doesn't help, let's see the exact case (including exact error
message) instead of a uselessly-abstract summary.

            regards, tom lane

pgsql-general by date:

Previous
From: Scott Marlowe
Date:
Subject: Re: weird problem with grants
Next
From: Martijn van Oosterhout
Date:
Subject: Re: Duplicate primary keys/rows