Re: Removing a user's password

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: Removing a user's password
Дата
Msg-id 200305261855.h4QItxb11771@candle.pha.pa.us
обсуждение исходный текст
Ответ на Re: Removing a user's password  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Tom Lane wrote:
> Bruce Momjian <pgman@candle.pha.pa.us> writes:
> > Tom Lane wrote:
> >> If you set VALID UNTIL to 'now' (or sometime in the past), you've
> >> effectively prevented him from logging in with the password ---
> >> more effectively than setting the password to NULL, since if the
> >> user is still logged in he can just undo that.  I don't think we
> >> really need to do anything more here.
> 
> > Well, can they undo the VALID UNTIL too?
> 
> No: a non-superuser can only set his password, not any other fields of
> his pg_shadow entry.
> 
> > I think at a minimum we need
> > to document the proper procedure for removing a password.  I see NULL as
> > a more logical way of removing the password rather than playing with
> > VALID UNTIL.
> 
> It may be more logical, but it doesn't work as well.

If a non-super user sets his own password, how does he unset it if he
can't use VALID UNTIL?  Is there no valid reason to unset it? 
Obviously, almost no one is asking for this feature so we may be OK, but
I do want to document using VALID UNTIL to disable a password.

--  Bruce Momjian                        |  http://candle.pha.pa.us pgman@candle.pha.pa.us               |  (610)
359-1001+  If your life is a hard drive,     |  13 Roberts Road +  Christ can be your backup.        |  Newtown Square,
Pennsylvania19073
 


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Removing a user's password
Следующее
От: Tom Lane
Дата:
Сообщение: Re: v7.3.3 bundled ... please test ...