Movatterモバイル変換


[0]ホーム

URL:



Facebook
Postgres Pro
Facebook
Downloads
20.4. Dropping Roles
Prev UpChapter 20. Database RolesHome Next

20.4. Dropping Roles#

Because roles can own database objects and can hold privileges to access other objects, dropping a role is often not just a matter of a quickDROP ROLE. Any objects owned by the role must first be dropped or reassigned to other owners; and any permissions granted to the role must be revoked.

Ownership of objects can be transferred one at a time usingALTER commands, for example:

ALTER TABLE bobs_table OWNER TO alice;

Alternatively, theREASSIGN OWNED command can be used to reassign ownership of all objects owned by the role-to-be-dropped to a single other role. BecauseREASSIGN OWNED cannot access objects in other databases, it is necessary to run it in each database that contains objects owned by the role. (Note that the first suchREASSIGN OWNED will change the ownership of any shared-across-databases objects, that is databases or tablespaces, that are owned by the role-to-be-dropped.)

Once any valuable objects have been transferred to new owners, any remaining objects owned by the role-to-be-dropped can be dropped with theDROP OWNED command. Again, this command cannot access objects in other databases, so it is necessary to run it in each database that contains objects owned by the role. Also,DROP OWNED will not drop entire databases or tablespaces, so it is necessary to do that manually if the role owns any databases or tablespaces that have not been transferred to new owners.

DROP OWNED also takes care of removing any privileges granted to the target role for objects that do not belong to it. BecauseREASSIGN OWNED does not touch such objects, it's typically necessary to run bothREASSIGN OWNED andDROP OWNED (in that order!) to fully remove the dependencies of a role to be dropped.

In short then, the most general recipe for removing a role that has been used to own objects is:

REASSIGN OWNED BY doomed_role TO successor_role;DROP OWNED BY doomed_role;-- repeat the above commands in each database of the clusterDROP ROLE doomed_role;

When not all owned objects are to be transferred to the same successor owner, it's best to handle the exceptions manually and then perform the above steps to mop up.

IfDROP ROLE is attempted while dependent objects still remain, it will issue messages identifying which objects need to be reassigned or dropped.


Prev Up Next
20.3. Role Membership Home 20.5. Predefined Roles
pdfepub
Go to Postgres Pro Standard 17
By continuing to browse this website, you agree to the use of cookies. Go toPrivacy Policy.

[8]ページ先頭

©2009-2025 Movatter.jp