1. Should we make the owner aclitem NEVER appear in the acl list? ie. when we do the first grant on an object, we don't put in a default acl for the owner. Instead we special case the aclcheck to always allow the owner full privilieges? Also, if the first grant was 'select' for the 'other' user, and then we changed the owner to the 'other' user, should we erase the 'other' user's aclitem?
I forgot to mention - under this schema grants/revokes to the owner become no-ops.
Chris
---------------------------(end of broadcast)--------------------------- TIP 4: Don't 'kill -9' the postmaster