Re: has_privs_of_role vs. is_member_of_role, redux - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: has_privs_of_role vs. is_member_of_role, redux
Date
Msg-id YzIAVzGYEQRRgn7j@tamriel.snowman.net
Whole thread Raw
In response to Re: has_privs_of_role vs. is_member_of_role, redux  (Wolfgang Walther <walther@technowledgy.de>)
List pgsql-hackers
Greetings,

* Wolfgang Walther (walther@technowledgy.de) wrote:
> Robert Haas:
> > I don't think we're going to be very happy if we redefine inheriting
> > the privileges of another role to mean inheriting only some of them.
> > That seems pretty counterintuitive to me. I also think that this
> > particular definition is pretty fuzzy.
>
> Scratch my previous suggestion. A new, less fuzyy definition would be:
> Ownership is not a privilege itself and as such not inheritable.

One of the reasons the role system was brought into being was explicitly
to allow other roles to have ownership-level rights on objects that they
didn't directly own.

I don't see us changing that.

Thanks,

Stephen

Attachment

pgsql-hackers by date:

Previous
From: Stephen Frost
Date:
Subject: Re: has_privs_of_role vs. is_member_of_role, redux
Next
From: Andres Freund
Date:
Subject: Re: [RFC] building postgres with meson - v13