Files

17 lines
805 B
SQL

-- ThothII — ruolo DWH read-only (schema datawarehouse).
-- Eseguire sulla stessa istanza Postgres usata da ThothII (porta 5438, accesso diretto).
-- Sostituire :PWD con un secret forte al momento dell'esecuzione:
-- psql -h localhost -p 5438 -U postgres -d postgres -v PWD='<secret>' -f 10-dwh-roles.sql
DO $$
BEGIN
IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'thoth_dwh_reader') THEN
CREATE ROLE thoth_dwh_reader LOGIN;
END IF;
END $$;
-- :'PWD' va fuori dal DO (psql non interpola nelle stringhe dollar-quoted)
ALTER ROLE thoth_dwh_reader PASSWORD :'PWD';
GRANT USAGE ON SCHEMA datawarehouse TO thoth_dwh_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA datawarehouse TO thoth_dwh_reader;
ALTER DEFAULT PRIVILEGES IN SCHEMA datawarehouse
GRANT SELECT ON TABLES TO thoth_dwh_reader;