Re: [PATCH] New predefined role pg_manage_extensions

Поиск
Список
Период
Сортировка
От Jelte Fennema-Nio
Тема Re: [PATCH] New predefined role pg_manage_extensions
Дата
Msg-id CAGECzQQ2HB85N9PjTAdDTpFCciQmpeE2PcXbc8EKhSF=RPi3fA@mail.gmail.com
обсуждение исходный текст
Ответ на [PATCH] New predefined role pg_manage_extensions  (Michael Banck <mbanck@gmx.net>)
Ответы Re: [PATCH] New predefined role pg_manage_extensions  (Michael Banck <mbanck@gmx.net>)
Список pgsql-hackers
On Fri, 12 Jan 2024 at 15:53, Michael Banck <mbanck@gmx.net> wrote:
> I propose to add a new predefined role to Postgres,
> pg_manage_extensions. The idea is that it allows Superusers to delegate
> the rights to create, update or delete extensions to other roles, even
> if those extensions are not trusted or those users are not the database
> owner.

I agree that extension creation is one of the main reasons people
require superuser access, and I think it would be beneficial to try to
reduce that. But I'm not sure that such a pg_manage_extensions role
would have any fewer permissions than superuser in practice. Afaik
many extensions that are not marked as trusted, are not trusted
because they would allow fairly trivial privilege escalation to
superuser if they were.



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Heikki Linnakangas
Дата:
Сообщение: Re: Stack overflow issue
Следующее
От: Peter Eisentraut
Дата:
Сообщение: Re: Make all Perl warnings fatal