Re: [GENERAL] Restricting the CREATEROLE privilege

2010-02-25 Thread Alex Hunsaker
On Thu, Feb 25, 2010 at 01:26, Wappler, Robert rwapp...@ophardt.com wrote: Good Morning, is there a way to limit the CREATEROLE privilege to a specific database? I currently set up an automated integration test environment. This includes a database owned by a specific user which should have

Re: [GENERAL] Restricting the CREATEROLE privilege

2010-02-25 Thread Wappler, Robert
On 2010-02-25, Alex Hunsaker wrote: You could create a base role that does not have connect privileges on the other databases. Then just inherit from that role. Something like: CREATE ROLE base_user; REVOKE CONNECT ON database from base_user; ... CREATE ROLE my_user inherit base_user;

Re: [GENERAL] Restricting the CREATEROLE privilege

2010-02-25 Thread Alex Hunsaker
On Thu, Feb 25, 2010 at 08:22, Wappler, Robert rwapp...@ophardt.com wrote: Unfortunately, base_user inherits the connect privileges from role PUBLIC, regardless, whether it was created with NOINHERIT. Yeah, IMO the documentation does not really spell out that limitation. How about changing