| From: | Guillaume Lelarge <guillaume(at)lelarge(dot)info> |
|---|---|
| To: | Derrick Rice <derrick(dot)rice(at)gmail(dot)com> |
| Cc: | pgsql-docs(at)postgresql(dot)org |
| Subject: | Re: DROP TABLE can be issued by schema owner as well as table owner |
| Date: | 2011-05-20 16:18:13 |
| Message-ID: | 4DD69445.3070507@lelarge.info |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-docs |
Le 05/20/2011 05:42 PM, Derrick Rice a écrit :
> According to
>
> http://www.postgresql.org/docs/9.0/interactive/sql-droptable.html
>
> "DROP TABLE removes tables from the database. Only its owner can drop a
> table."
>
> In fact, the schema owner can drop the table, which is clearly stated here:
>
> http://www.postgresql.org/docs/9.0/interactive/sql-dropschema.html
>
> "A schema can only be dropped by its owner or a superuser. Note that the
> owner can drop the schema (and thereby all contained objects) even if he
> does not own some of the objects within the schema."
>
> There are likely other places besides the DROP TABLE page which can be
> misleading with regard to ability to drop a table. This should be made more
> clear, since in (possibly contrived) circumstances, being able to drop a
> table and recreate an exactly similar table may be a vulnerability (if the
> design assumed the table could only be dropped by the owner).
>
> (Just joined the list to post this -- sorry if it has already been brought
> up)
>
Well, for a specific object, any superuser, the database owner, the
schema owner, and the object owner could drop the object. This is not a
vulnerability.
--
Guillaume
http://www.postgresql.fr
http://dalibo.com
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Derrick Rice | 2011-05-20 16:35:24 | Re: DROP TABLE can be issued by schema owner as well as table owner |
| Previous Message | Derrick Rice | 2011-05-20 15:42:32 | DROP TABLE can be issued by schema owner as well as table owner |