Re: improving user.c error messages

Поиск
Список
Период
Сортировка
Искать
От
Nathan Bossart
Тема
Re: improving user.c error messages
Дата
Msg-id
20230220225852.GA3940888@nathanxps13
Ответ на
Список
Дерево обсуждения
almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet tushar <tushar.ahuja@enterprisedb.com>
Re: almost-super-user problems that we haven't fixed yet tushar <tushar.ahuja@enterprisedb.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet tushar <tushar.ahuja@enterprisedb.com>
Re: almost-super-user problems that we haven't fixed yet tushar <tushar.ahuja@enterprisedb.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Nathan Bossart <nathandbossart@gmail.com>
Re: almost-super-user problems that we haven't fixed yet Robert Haas <robertmhaas@gmail.com>
CREATEROLE users vs. role properties Robert Haas <robertmhaas@gmail.com>
Re: CREATEROLE users vs. role properties Nathan Bossart <nathandbossart@gmail.com>
Re: CREATEROLE users vs. role properties tushar <tushar.ahuja@enterprisedb.com>
Re: CREATEROLE users vs. role properties tushar <tushar.ahuja@enterprisedb.com>
Re: CREATEROLE users vs. role properties Robert Haas <robertmhaas@gmail.com>
Re: CREATEROLE users vs. role properties tushar <tushar.ahuja@enterprisedb.com>
Re: CREATEROLE users vs. role properties Robert Haas <robertmhaas@gmail.com>
Re: CREATEROLE users vs. role properties tushar <tushar.ahuja@enterprisedb.com>
Re: CREATEROLE users vs. role properties Robert Haas <robertmhaas@gmail.com>
Re: CREATEROLE users vs. role properties Robert Haas <robertmhaas@gmail.com>
improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Alvaro Herrera <alvherre@alvh.no-ip.org>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Robert Haas <robertmhaas@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Tom Lane <tgl@sss.pgh.pa.us>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Tom Lane <tgl@sss.pgh.pa.us>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Alvaro Herrera <alvherre@alvh.no-ip.org>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Tom Lane <tgl@sss.pgh.pa.us>
Re: improving user.c error messages Peter Eisentraut <peter.eisentraut@enterprisedb.com>
Re: improving user.c error messages Robert Haas <robertmhaas@gmail.com>
Re: improving user.c error messages Nathan Bossart <nathandbossart@gmail.com>
Re: improving user.c error messages Robert Haas <robertmhaas@gmail.com>
Re: improving user.c error messages Tom Lane <tgl@sss.pgh.pa.us>
Re: improving user.c error messages Alvaro Herrera <alvherre@alvh.no-ip.org>
On Mon, Feb 20, 2023 at 11:02:10AM -0800, Nathan Bossart wrote:
> On Mon, Feb 20, 2023 at 08:54:48AM +0100, Peter Eisentraut wrote:
>> I'm concerned about the loose use of "privilege" here.  A privilege is
>> something I can grant.  So if someone doesn't have the "REPLICATION
>> privilege", as in the above example, I would expect to be able to do "GRANT
>> REPLICATION TO someuser".  Since that is not what is happening, we should
>> use some other term.  The documentation around CREATE USER uses the terms
>> "attribute" and "option" (and also "privilege") for these things.
> 
> Good point.  I will adjust these to use "attribute" instead.

done in v6

>> Similarly -- this is an existing issue but we might as well look at it -- in
>> something like
>> 
>>     must be superuser or a role with privileges of the
>>     pg_write_server_files role
>> 
>> the phrase "a role with the privileges of that other role" seems ambiguous.
>> Doesn't it really mean you must be a member of that role?
> 
> Membership alone is not sufficient.  You must also inherit the privileges
> of the role via the INHERIT option.  I thought about making this something
> like
> 
> 	must have the INHERIT option on role %s
> 
> but I'm not sure that's accurate either.  That wording makes it sound lіke
> you need to be granted membership to the role directly WITH INHERIT OPTION,
> but what you really need is membership, direct or indirect, with an INHERIT
> chain up to the role in question.  However, it looks like "must have the
> ADMIN option on role %s" is used to mean something similar, so perhaps I am
> overthinking it.

For now, I've reworded these as "must inherit privileges of".

-- 
Nathan Bossart
Amazon Web Services: https://aws.amazon.com
В списке pgsql-hackers по дате отправления
От: Michael Paquier
Дата:
Сообщение: Re: pg_walinspect memory leaks
От: Jim Jones
Дата:
FAQ