Re: [PATCHES] CATALOG/NOCATALOG for new users

2004-02-02 Thread Peter Eisentraut
Tom Lane wrote: > As an example, it might make more sense to create a separate flag bit > that simply grants the ability to add and delete users > (non-superusers, presumably), with none of the other attributes of a > superuser. If I recall your original concern properly, this would be > a safer f

Re: [PATCHES] CATALOG/NOCATALOG for new users

2003-12-24 Thread Tom Lane
Christopher Kings-Lynne <[EMAIL PROTECTED]> writes: > 1. Should we only allow users who currently hold the catalog perm to grant > it to others? I think yes, since otherwise a regular superuser can create > themselves another account with the catalog priv. That brings up the whole business of jus

[PATCHES] CATALOG/NOCATALOG for new users

2003-12-24 Thread Christopher Kings-Lynne
This is a preliminary patch - don't commit it. What this patch adds are the CATALOG and NOCATALOG clauses to the CREATE USER and ALTER USER commands. These clauses affect the usecatupd column. This makes it easy to create superusers who cannot manually modify columns (a very nasty power...) The