Permissions not removed when group dropped - Mailing list pgsql-admin

From Harris, Richard
Subject Permissions not removed when group dropped
Date
Msg-id E2F600719FA6FF438A680A22A00DA43C05F7AA2C@EXCHANGEDS01.ds.ad.adp.com
Whole thread Raw
Responses Re: Permissions not removed when group dropped  (Alvaro Herrera <alvherre@surnet.cl>)
List pgsql-admin
Hi,

I'm using PostgreSQL 8.0. I created a group called grpA and granted grpA
'SELECT' permission on view viewA. When I dropped grpA and created group
grpB, group grpB 'automatically' has SELECT permission to viewA. After
dropping a group with permission to a view, I see that the permission
stored in the relacl field fo pg_class is changed from the group name to
the sysid of the dropped group. When a new group is created, it gets a
sysid that is one greater than the largest of the sysid (e.g., the sysid
of the last group dropped).  Thus the new group may 'inherit' the
permissions of a dropped group.

I have not found this behavior documented any where. Is this behavior
intended? What do I need to do so that when I drop a group all the
permissions of the group are also 'dropped' (i.e., cleared from the
relacl field)?

Thanks for you help.

Rich Harris

pgsql-admin by date:

Previous
From: "Lee Wu"
Date:
Subject: /tmp/.s.PGSQL.5432
Next
From: Alvaro Herrera
Date:
Subject: Re: Permissions not removed when group dropped