Re: How restrict select on a view ? - Mailing list pgsql-general

From Merlin Moncure
Subject Re: How restrict select on a view ?
Date
Msg-id b42b73150812160635x571eb146o9b30a4a8c78c2af1@mail.gmail.com
Whole thread Raw
In response to Re: How restrict select on a view ?  (Klint Gore <kgore4@une.edu.au>)
Responses Re: How restrict select on a view ?  (Andreas <maps.on@gmx.net>)
List pgsql-general
On Mon, Dec 15, 2008 at 9:38 PM, Klint Gore <kgore4@une.edu.au> wrote:
> Andreas wrote:
>>
>> I'd like to have a view only to be used by certain users.
>> The tables are public.
>>
>> Can this only be done by restricting access to the tables?
>>
>
> GRANT/REVOKE works on views
> revoke all on aview from public;
> grant select on aview to user1;
>
> As Raymond pointed out, if user2 knows what the definition of aview is, they
> can just run it against the raw tables.
> e.g.
> create view aview as select * from pg_proc;
> revoke all on aview from public;
> grant select on aview to user1;
> set session authorization user2;
> select * from aview;  -- fails
> select * from pg_proc;  -- works and gives the same result

Yes, but:

* you can still \d the view (or \d equivalent in sql) which shows it's
definition
* if you can \d view, you can 'create temporary view' with the same
definition on public tables

what does this get you?

merlin

pgsql-general by date:

Previous
From: Alvaro Herrera
Date:
Subject: Re: what happens to indexes when TRUNCATEing
Next
From: Angel
Date:
Subject: Re: tup_returned/ tup_fetched