diff options
author | Stephen Frost <sfrost@snowman.net> | 2015-01-29 21:59:34 -0500 |
---|---|---|
committer | Stephen Frost <sfrost@snowman.net> | 2015-01-29 21:59:34 -0500 |
commit | 32bf6ee6ab5cdfa4247f984f864860d988a58dfe (patch) | |
tree | b90d78cb8cddd7b0f7948817cc6a1c747923d8a4 /src | |
parent | e77043055f5b80bfc173ef67795cb36fdcef7f40 (diff) | |
download | postgresql-32bf6ee6ab5cdfa4247f984f864860d988a58dfe.tar.gz postgresql-32bf6ee6ab5cdfa4247f984f864860d988a58dfe.zip |
Fix BuildIndexValueDescription for expressions
In 804b6b6db4dcfc590a468e7be390738f9f7755fb we modified
BuildIndexValueDescription to pay attention to which columns are visible
to the user, but unfortunatley that commit neglected to consider indexes
which are built on expressions.
Handle error-reporting of violations of constraint indexes based on
expressions by not returning any detail when the user does not have
table-level SELECT rights.
Backpatch to 9.0, as the prior commit was.
Pointed out by Tom.
Diffstat (limited to 'src')
-rw-r--r-- | src/backend/access/index/genam.c | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/src/backend/access/index/genam.c b/src/backend/access/index/genam.c index 358830c47f0..e6e4d28b74f 100644 --- a/src/backend/access/index/genam.c +++ b/src/backend/access/index/genam.c @@ -222,10 +222,15 @@ BuildIndexValueDescription(Relation indexRelation, { AttrNumber attnum = idxrec->indkey.values[keyno]; - aclresult = pg_attribute_aclcheck(indrelid, attnum, GetUserId(), - ACL_SELECT); - - if (aclresult != ACLCHECK_OK) + /* + * Note that if attnum == InvalidAttrNumber, then this is an + * index based on an expression and we return no detail rather + * than try to figure out what column(s) the expression includes + * and if the user has SELECT rights on them. + */ + if (attnum == InvalidAttrNumber || + pg_attribute_aclcheck(indrelid, attnum, GetUserId(), + ACL_SELECT) != ACLCHECK_OK) { /* No access, so clean up and return */ ReleaseSysCache(ht_idx); |