Re: superusers are members of all roles?

Поиск
Список
Период
Сортировка
От Josh Berkus
Тема Re: superusers are members of all roles?
Дата
Msg-id 4D9D3BE6.7000303@agliodbs.com
обсуждение исходный текст
Ответ на Re: superusers are members of all roles?  (Robert Haas <robertmhaas@gmail.com>)
Список pgsql-hackers
> See bug #5763, and subsequent emails.  Short version: Tom argued it
> wasn't a bug; Peter and I felt that it was.

Add my vote: it's a bug.

Users who fall afoul of this will spend *hours* trying to debug this
before they stumble on the correct answer.  pg_hba.conf is confusing
enough as it is.

The only reason we don't get more bug reports on this is that not very
many users know about using group roles in pg_hba.conf (and few enough
users are using group roles in the first place).

If we're not going to fix this, then we need a big warning in the docs
and the pg_hba.conf file:

"NOTE: Please make sure that at least one rule in pg_hba.conf matches
superuser access before any reject rules"

-- 
Josh Berkus
PostgreSQL Experts Inc.
http://pgexperts.com


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: too many dotted names
Следующее
От: Tom Lane
Дата:
Сообщение: Re: superusers are members of all roles?