Expand description
Check, grant and revoke the ACL of an object with one grantable privilege, as PostgreSQL’s aclchk.c does for routine EXECUTE and type USAGE. An absent ACL is the default ACL: the privilege for PUBLIC and for the owner. Owners always hold grant options.
Functions§
- acl_
roles - The owner and every role named by the ACL.
- acl_
warning - The WARNING of a GRANT or REVOKE whose current user holds no grant option, naming the object without its schema.
- added_
acl_ roles - Record the names of roles that an ACL change newly references, excluding the owners.
- bind_
grantees - Bind grantee names to role incarnations; PUBLIC stays unbound.
- explicit_
acl - The ACL a GRANT or REVOKE stores:
ExecGrant_commonsubstitutes the default ACL for a missing one and always writes its result, so the default becomes explicit even when the command changes nothing. - grant
- Add the privilege, merging the grant option into an existing entry from the same grantor.
- grant_
option_ roles - Roles whose grant option is reachable from the owner through grant-option entries.
- privilege_
allowed - Whether a role holding
has_rolememberships may use the object, or grant it whengrant_optionis set. - revoke
- Remove the privilege or only its grant option; revoking what the grantor did not grant changes nothing, and
ExecGrant_*warns only when the grantor holds no grant option. Privileges granted through a lost grant option require CASCADE. - rewrite_
owner aclnewowner: the new owner replaces the old one as grantee and grantor, and entries that become identical merge.- select_
grantor select_best_grantor: the owner when the current user inherits it, then the current user’s own grant option, then an inherited role’s grant option.Nonemeans the command grants or revokes nothing and warns.- validate_
acl - Validate the role identities and grant paths of an ACL: every endpoint names a role incarnation, PUBLIC holds no grant option, no grant path repeats, and every grantor’s grant option is reachable from the owner.