Re: Privileges on public schema can't be revoked? - Mailing list pgsql-general

From Jim Nasby
Subject Re: Privileges on public schema can't be revoked?
Date
Msg-id 7b9bbe51-6b6d-dd34-77be-a4043c36d323@BlueTreble.com
Whole thread Raw
In response to Re: Privileges on public schema can't be revoked?  (Greg Fodor <gfodor@gmail.com>)
List pgsql-general
On 9/6/16 3:16 PM, Greg Fodor wrote:
> It seems that functionality that lets a superuser quickly audit the
> privileges for a user (including those granted via PUBLIC) would be
> really helpful for diagnosing cases where that user can do something
> they shouldn't be allowed to.

That's actually relatively easy to do today; see the has_*_privilege()
functions.

You might also find http://pgxn.org/dist/pg_acl useful.
--
Jim Nasby, Data Architect, Blue Treble Consulting, Austin TX
Experts in Analytics, Data Architecture and PostgreSQL
Data in Trouble? Get it in Treble! http://BlueTreble.com
855-TREBLE2 (855-873-2532)   mobile: 512-569-9461


pgsql-general by date:

Previous
From: Jim Nasby
Date:
Subject: Re: Materialized view auto refresh
Next
From: Patrick B
Date:
Subject: Re: Postgres UPGRADE from 9.2 to 9.4