Skip to main content
Question

Inappropriate usage of meta-function ("has_table_privilege")

  • November 19, 2020
  • 0 replies
  • 3 views

Bryan_H
Forum|alt.badge.img+2

What are the limits on HAS_TABLE_PRIVILEGE?
I have a customer who found that HAS_TABLE_PRIVILEGE does not check whether you have USAGE on the schema, so SELECT HAS_TABLE_PRIVILEGE('user','schema1.table1','select'); will still return true if user can SELECT from table1 even if they lack USAGE on schema1.
To try to work around this, we tried various joins and conditions like this:
dbadmin=> select 1 from grants where grantee = 'bryan' and object_name = 'acl' and object_type = 'SCHEMA' and privileges_description ILIKE '%USAGE%' UNION ALL select has_table_privilege('bryan','acl.acl1','select');
ERROR 6809: Inappropriate usage of meta-function ("has_table_privilege")
But it appears the EE will reject any query that is not a flat SELECT HAS_TABLE_PRIVILEGE();
This looks like it needs a JIRA, or at least a doc change to clarify what is allowed and maybe why. I figured I would ask here first.