Re: [BUGS] Probably a security bug in PostgreSQL rule system

2004-01-13 Thread Tom Lane
"Sergey N. Yatskevich" <[EMAIL PROTECTED]> writes: > Next -- test and it's output, that shows, that if view has INSERT, > UPDATE and DELETE rules then _ANY_ user can insert, update and delete > data in tables, that affected by this rules even user has no INSERT, > UPDATE and DELETE privileges on vi

[BUGS] Probably a security bug in PostgreSQL rule system

2004-01-10 Thread Sergey N. Yatskevich
At begin some citations from PostgreSQL documentation: 34.4. Rules and Privileges Rewrite rules don't have a separate owner. The owner of a relation (table or view) is automatically the owner of the rewrite rules that are defined for it. The PostgreSQL rule system changes the behavior of the de