Re: Streaming replication as a separate permissions

From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Peter Eisentraut <peter_e(at)gmx(dot)net>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Stephen Frost <sfrost(at)snowman(dot)net>, Robert Haas <robertmhaas(at)gmail(dot)com>, Florian Pflug <fgp(at)phlo(dot)org>, PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Streaming replication as a separate permissions
Date: 2010-12-31 14:38:29
Message-ID: AANLkTinTL4_vR+yyTBevLXV5e6BAbC3GTZhTUMhpLb1-@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Thu, Dec 30, 2010 at 15:54, Peter Eisentraut <peter_e(at)gmx(dot)net> wrote:
> On ons, 2010-12-29 at 11:09 +0100, Magnus Hagander wrote:
>> I've applied this version (with some minor typo-fixes).
>
> This page is now somewhat invalidated:
>
> http://developer.postgresql.org/pgdocs/postgres/role-attributes.html

Hmm. Somehow I missed that page completely when looking through the
docs. I'll go update that.

> First, it doesn't mention the replication privilege, and second it
> continues to claim that superuser status bypasses all permission checks.

Well, that was *already* wrong.

superuser doesn't bypass NOLOGIN.

That doesn't mean it shouldn't be fixed, but that's independent of the
replication role.

--
 Magnus Hagander
 Me: http://www.hagander.net/
 Work: http://www.redpill-linpro.com/

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Joachim Wieland 2010-12-31 14:38:51 Re: Snapshot synchronization, again...
Previous Message Robert Haas 2010-12-31 14:13:50 Re: Sync Rep Design