Re: Clarification on Role Access Rights to Table Indexes

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Ayush Vatsa <ayushvatsa1810(at)gmail(dot)com>
Cc: "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Clarification on Role Access Rights to Table Indexes
Date: 2025-02-17 19:57:43
Message-ID: 908583.1739822263@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-hackers

Ayush Vatsa <ayushvatsa1810(at)gmail(dot)com> writes:
>> As it stands, a superuser can prewarm an index (because she bypasses all
>> privilege checks including this one), but nobody else can.

> That's not fully true. Any role can prewarm an index if the role has the
> correct privileges.

Ah, right. An index will have null pg_class.relacl, which'll be
interpreted as "owner has all rights", so it will work for the
table owner too. Likely this explains the lack of prior complaints.
It's still a poor design IMO.

regards, tom lane

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Laurenz Albe 2025-02-17 19:58:49 Re: Clarification on Role Access Rights to Table Indexes
Previous Message Ayush Vatsa 2025-02-17 19:42:44 Re: Clarification on Role Access Rights to Table Indexes

Browse pgsql-hackers by date

  From Date Subject
Next Message Laurenz Albe 2025-02-17 19:58:49 Re: Clarification on Role Access Rights to Table Indexes
Previous Message Sergey Prokhorenko 2025-02-17 19:56:58 Re: UUID v7