Re: DB getTables() and permissions, bug #5800
| From: | Joshua Eichorn | Date: | Thu, 27 Oct 2005 21:57:59 +0000 |
| Subject: | Re: DB getTables() and permissions, bug #5800 | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-40321@lists.php.net to get a copy of this message | ||
Leo Lutz wrote:
DB/Dataproject/Generate halts when it tries to get tableinfo on a table that doesn't have usage permissions. This problem arises because in Postgres the getTables() function returns all tables whether the user has privileges for them or not. So my question, is this appropriate to fix in the pgsql driver or in the way Generate handles bad permissions. These are the options I've come up with (not inclusive): Option 1) Fixing it in DB It appears that it's not possible to deny 'USAGE' per table in MySQL, so the problem doesn't occur for that DB. How does this work in other DB's? Would it be a good idea to check privileges before returning that the table exists? This is easy to do but I'm not sure if it would break acceptable behavior. Option 2) Fix in Generate.php Have it ignore tables that it doesn't get info for so that it doesn't halt. Maybe have it spit out "Ignoring table: mytable." To be able to tell the actual reason for failure we would need to modify DB/pgsql.php to respond with more than the current "return $this->pgsqlRaiseError(DB_ERROR_NEED_MORE_DATA);". Again, not sure how that works with acceptable behavior. Mysql and im assuming most other db's can actually do permissions down to the column level.http://dev.mysql.com/doc/refman/5.0/en/grant.html I'm not sure how this effects your generation fixing plans, but it might be something worth taking into account. -josh