Add code to setup permissions properly

Based on roles and by default closing everything. No need to tweak
things outside of the extension.
This commit is contained in:
Rafa de la Torre
2015-11-11 19:23:01 +00:00
parent 4e7525cc88
commit a7748f71c3
5 changed files with 55 additions and 0 deletions
+4
View File
@@ -12,3 +12,7 @@ SELECT cdb_geocoder_client._config_set('db_server_config', '{"connection_str": "
-- Mock the server schema
CREATE SCHEMA cdb_geocoder_server;
-- Create a test user to check permissions
DROP ROLE IF EXISTS test_regular_user;
CREATE ROLE test_regular_user;
GRANT publicuser TO test_regular_user;
+19
View File
@@ -0,0 +1,19 @@
-- Use regular user role
SET ROLE test_regular_user;
-- Exercise the public function
-- it is public, it shall work
SELECT cdb_geocoder_client.geocode_admin0_polygons('Spain');
NOTICE: cdb_geocoder_client._geocode_admin0_polygons(3): [contrib_regression] REMOTE NOTICE: cbd_geocoder_server.geocode_admin0_polygons invoked with params (postgres, some_transaction_id, Spain)
CONTEXT: SQL statement "SELECT cdb_geocoder_client._geocode_admin0_polygons(session_user, txid_current(), country_name)"
PL/pgSQL function cdb_geocoder_client.geocode_admin0_polygons(text) line 5 at SQL statement
geocode_admin0_polygons
-------------------------
(1 row)
-- Check the regular user has no permissions on private functions
SELECT cdb_geocoder_client._geocode_admin0_polygons('evil_user', 666, 'Hell');
ERROR: permission denied for function _geocode_admin0_polygons
-- Check the regular user cannot look into config table
SELECT * from cdb_geocoder_client._config;
ERROR: permission denied for relation _config