Re: New predefined roles- 'pg_read/write_all_data'

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Michael Banck <michael(dot)banck(at)credativ(dot)de>
Cc: gkokolatos(at)pm(dot)me, Anastasia Lubennikova <a(dot)lubennikova(at)postgrespro(dot)ru>, "pgsql-hackers(at)lists(dot)postgresql(dot)org" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: New predefined roles- 'pg_read/write_all_data'
Date: 2021-08-27 22:33:33
Message-ID: 20210827223333.GW17906@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Greetings,

* Michael Banck (michael(dot)banck(at)credativ(dot)de) wrote:
> On Thu, Apr 01, 2021 at 04:00:06PM -0400, Stephen Frost wrote:
> > diff --git a/doc/src/sgml/user-manag.sgml b/doc/src/sgml/user-manag.sgml
> > index d171b13236..fe0bdb7599 100644
> > --- a/doc/src/sgml/user-manag.sgml
> > +++ b/doc/src/sgml/user-manag.sgml
> > @@ -518,6 +518,24 @@ DROP ROLE doomed_role;
> > </row>
> > </thead>
> > <tbody>
> > + <row>
> > + <entry>pg_read_all_data</entry>
> > + <entry>Read all data (tables, views, sequences), as if having SELECT
> > + rights on those objects, and USAGE rights on all schemas, even without
> > + having it explicitly. This role does not have the role attribute
> > + <literal>BYPASSRLS</literal> set. If RLS is being used, an administrator
> > + may wish to set <literal>BYPASSRLS</literal> on roles which this role is
> > + GRANTed to.</entry>
> > + </row>
> > + <row>
> > + <entry>pg_write_all_data</entry>
> > + <entry>Write all data (tables, views, sequences), as if having INSERT,
> > + UPDATE, and DELETE rights on those objects, and USAGE rights on all
> > + schemas, even without having it explicitly. This role does not have the
> > + role attribute <literal>BYPASSRLS</literal> set. If RLS is being used,
> > + an administrator may wish to set <literal>BYPASSRLS</literal> on roles
> > + which this role is GRANTed to.</entry>
> > + </row>
>
> Shouldn't those "SELECT", "INSERT" etc. be wrapped in <command> tags?

Yeah, good point, fixed.

Thanks!

Stephen

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Stephen Frost 2021-08-27 22:46:39 Re: pgsql: Deduplicate choice of horizon for a relation procarray.c.
Previous Message Stephen Frost 2021-08-27 22:27:20 Re: Can we get rid of repeated queries from pg_dump?