Skip to content

Add dynamic permissions test for the cat_tools grant model#43

Merged
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:extract-permissions-test
Jul 21, 2026
Merged

Add dynamic permissions test for the cat_tools grant model#43
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:extract-permissions-test

Conversation

@jnasbyupgrade

Copy link
Copy Markdown
Contributor

Extracted from #16 to shrink it.
Adds test/sql/permissions.sql and test/expected/permissions.out, a self-contained pgTap test that introspects pg_proc/pg_type in the cat_tools schema at runtime and asserts no_use_role is denied and use_role is granted EXECUTE/USAGE on every function and type present.
It has no hardcoded function list, so it runs unchanged against master's current (0.2.3) function set and will keep working as functions are added or removed.
Adapted from the #16 version: dropped the _cat_tools schema-level USAGE assertion, since on master nothing in _cat_tools is called by a public function at runtime, so cat_tools__usage has no USAGE grant there (unlike on new_functions, where new internal helpers require it).

Extracted from PR Postgres-Extensions#16 to shrink it.
Introspects pg_proc/pg_type in the cat_tools schema at runtime and asserts
no_use_role is denied and use_role is granted EXECUTE/USAGE on every function
and type present, so it needs no hardcoded function list and stays correct
as functions are added or removed.
Dropped the _cat_tools schema-level USAGE assertion from the original: on
master (0.2.3) nothing in _cat_tools is called by a public function at
runtime, so cat_tools__usage has no USAGE grant there, unlike on
new_functions where new internal helpers require it.
@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: df4408c8-7fcd-4145-9e3a-86041ea0d708

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jnasbyupgrade
jnasbyupgrade merged commit 72cebda into Postgres-Extensions:master Jul 21, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant