Re: Streaming replication as a separate permissions

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Streaming replication as a separate permissions
Дата
Msg-id 14807.1293464033@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Streaming replication as a separate permissions  (Magnus Hagander <magnus@hagander.net>)
Ответы Re: Streaming replication as a separate permissions  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-hackers
Magnus Hagander <magnus@hagander.net> writes:
> On Mon, Dec 27, 2010 at 10:53, Magnus Hagander <magnus@hagander.net> wrote:
>> We could quite easily make a replication role *never* be able to
>> connect to a non-walsender backend. That would mean that if you set
>> your role to WITH REPLICATION, it can *only* be used for replication
>> and nothing else (well, you could still SET ROLE to it, but given that
>> it's not a superuser (anymore), that doesn't have any security
>> implications.

> Actually, having implemented that and tested it, I realize that's a
> pretty bad idea.

OK, so if we're not going to recommend that REPLICATION roles be
NOLOGIN, we're back to the original question: should the REPLICATION
bit give any other special privileges?  I can see the point of allowing
such a user to issue pg_start_backup and pg_stop_backup.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: Reduce lock levels for ADD and DROP COLUMN
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: Streaming replication as a separate permissions