Re: Recognizing superuser in pg_hba.conf

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Recognizing superuser in pg_hba.conf
Дата
Msg-id 12997.1577998192@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Recognizing superuser in pg_hba.conf  (Andrew Gierth <andrew@tao11.riddles.org.uk>)
Ответы Re: Recognizing superuser in pg_hba.conf
Список pgsql-hackers
Andrew Gierth <andrew@tao11.riddles.org.uk> writes:
> "Tom" == Tom Lane <tgl@sss.pgh.pa.us> writes:
>  Tom> Meh. If the things aren't actually roles, I think this'd just add
>  Tom> confusion. Or were you proposing to implement them as roles? I'm
>  Tom> not sure if that would be practical in every case.

> In fact my original suggestion when this idea was discussed on IRC was
> to remove the current superuser flag and turn it into a role; but the
> issue then is that role membership is inherited and superuserness
> currently isn't, so that's a more intrusive change.

To cover the proposed functionality, you'd still need some way to
select not-superuser.  So I don't think this fully answers the need
even if we wanted to do it.

It's possible that role-ifying everything and then allowing "!role"
in the pg_hba.conf syntax would be enough.  Not sure though.

More generally, allowing inheritance of superuser scares me a bit
from a security standpoint.  I wouldn't mind turning all the other
legacy role properties into grantable roles, but I *like* the fact
that that one is special.

            regards, tom lane



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Jeff Janes
Дата:
Сообщение: Re: [PATCH] Increase the maximum value track_activity_query_size
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: Recognizing superuser in pg_hba.conf