On 05/06/2019 09:52, Laurenz Albe wrote:
Chris Withers wrote:
Is there any way to grant rights to a user such that they can drop and
re-create only a single database?
No; what I'd do if I needed that is to create a SECURITY DEFINER function
that is owned by a user with the CREATEDB privilege.
This function can be called by a normal user that has the EXECUTE privilege
on the function.

Don't forget to "SET search_path" on such a function (as mentioned in the
documentation).  It might also be a good idea to REVOKE EXECUTE on the
function from PUBLIC.
Thanks, that's a great idea! Is this pattern documented anywhere as a complete finished thing?

cheers,

Chris



Reply via email to