"Kaiting Chen" <kaitocracy(at)gmail(dot)com> writes:
> From this pg_hba configuration as the user 'kaiting.chen' is not in role
> 'service' the second entry in the table should be skipped and he should
> authenticate via GSSAPI. However this does not happen.
I believe the definition of "in role" we use here is "has the privileges
of role". Since kaiting.chen is a superuser, all privilege tests will
succeed for him, including that one. IOW, a superuser is automatically
a member of every role. This isn't a bug.
regards, tom lane
In response to
pgsql-bugs by date
|Next:||From: Jonathan Pool||Date: 2010-11-23 18:08:07|
|Subject: Documentation bug: Chapter 35.4, paragraph 4|
|Previous:||From: Jon Nelson||Date: 2010-11-23 14:37:02|
|Subject: Re: temporary tables, and lots of 0 byte files|