Re: Revoke for a new role - Mailing list pgsql-admin

From Milen A. Radev
Subject Re: Revoke for a new role
Date
Msg-id g2tur0$rtq$1@ger.gmane.org
Whole thread Raw
In response to Revoke for a new role  ("Rafael Domiciano" <rafael.domiciano@gmail.com>)
Responses Re: Revoke for a new role  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-admin
Rafael Domiciano написа:
> Hi folks,
>
> I'm new in this mailing list.
>
> I need to create a role (Postgres user) that cannot drop or create table,
> but can create TEMP tables. This role must do I, U and D normally.
>
> I have read some docs over the web and discovered that option to revoke
> "create table" doesn't exist.
>
> Can someone give me a light?!


For a role to be able to create tables (and other objects) it should
have "CREATE" privilege on the _schema_ in question. As for creating
temporary tables - "TEMP" ("TEMPORARY") privilege on the _database_ in
question.

Please check
http://www.postgresql.org/docs/current/static/sql-grant.html for details.

--
Milen A. Radev

pgsql-admin by date:

Previous
From: "Miracapillo Alessandro"
Date:
Subject: I: Purge Oid
Next
From: Tom Lane
Date:
Subject: Re: Revoke for a new role