Issue Details (XML | Word | Printable)

Key: CORE-5852
Type: Bug Bug
Status: Closed Closed
Resolution: Fixed
Priority: Major Major
Assignee: Roman Simakov
Reporter: Roman Simakov
Votes: 0
Watchers: 1
Operations

If you were logged in you would be able to see more operations.
Firebird Core

There is no check of existance generator and exception when privileges are granted

Created: 20/Jun/18 02:52 PM   Updated: 23/Jun/18 05:25 AM
Component/s: Engine
Affects Version/s: 4.0 Alpha 1, 3.0.3
Fix Version/s: 3.0.4, 4.0 Beta 1

QA Status: Done successfully


 Description  « Hide
RDB$TRIGGER9 checks that object exists. After adding USAGE privilege on generator and exception related checks were not added to RDB$TRIGGER9. As result we can grant privilege to non existing object. In the same time it's reaaly hard to maintain system triggers in clean BLR code and after protecting system tables from modifications we may move such checks to engine.

 All   Comments   Change History   Subversion Commits      Sort Order: Ascending order - Click to sort in descending order
Roman Simakov added a comment - 22/Jun/18 02:38 PM
I used the follow script to test:

set echo on;
create database '/tmp/1.fdb';

grant select on table t to user u;

create table t(i integer);
grant update(c) on table t to user u;

grant select on v to user u;
grant execute on procedure p to user u;
grant execute on function f to user u;
grant execute on package p to user u;
grant usage on exception e to user u;
grant usage on generator g to user u;
grant usage on sequence s to user u;

create view v(i) as select i from t;
grant select on table v to user u;