You should not need to, however, at this time we are not explicitly setting it for the schema and schema user. I've logged TE-19687 to address this.
I can tell you that I've just installed some stored procedures and they fail with a permissions issue. I will investigate more in the morning.
I can tell you that I've just installed some stored procedures and they fail with a permissions issue. I will investigate more in the morning.
Right, it's a gap which is why I've logged TE-19687 to fix the issue.
After further analyzing the issue, we are assigning the correct permissions in our hosting environment already. TE-19687 has been closed. You will not need to grant exec permission when installing your plugins. In your own environment or in an on-premise environment, you will be responsible for assigning the plugin user account the correct permissions. The following permissions should work:
ALTER USER [{NewUser}] WITH DEFAULT_SCHEMA = [{pluginSchema.Schema}];
GRANT SELECT ON SCHEMA::[Api] TO [{NewUser}]; -- To access the permissions view
GRANT SELECT, INSERT, UPDATE, DELETE, EXECUTE, ALTER ON SCHEMA::[{pluginSchema.Schema}] TO [{NewUser}];
GRANT CREATE TABLE, CREATE VIEW, CREATE FUNCTION, CREATE PROCEDURE, CREATE TYPE, CREATE SYNONYM TO [{NewUser}];This is basically what we created which is pretty much the same
CREATE LOGIN developer WITH PASSWORD = 'StrongSecurePassword123!'; GO USE community_app; GO CREATE USER developer FOR LOGIN developer; GO CREATE SCHEMA dev AUTHORIZATION [developer]; GO ALTER USER [developer] WITH DEFAULT_SCHEMA = [dev]; GO GRANT SELECT ON SCHEMA::[Api] TO [developer]; -- To access the permissions view GO GRANT SELECT, INSERT, UPDATE, DELETE, EXECUTE, ALTER ON SCHEMA::[dev] TO [developer]; GO GRANT CREATE TABLE, CREATE VIEW, CREATE FUNCTION, CREATE PROCEDURE, CREATE TYPE, CREATE SYNONYM TO [developer]; GO