Re: Delegating superuser tasks to new security roles

From: torikoshia <torikoshia(at)oss(dot)nttdata(dot)com>
To: Mark Dilger <mark(dot)dilger(at)enterprisedb(dot)com>
Cc: Jacob Champion <pchampion(at)vmware(dot)com>, sfrost(at)snowman(dot)net, robertmhaas(at)gmail(dot)com, pgsql-hackers(at)postgresql(dot)org, tgl(at)sss(dot)pgh(dot)pa(dot)us, chap(at)anastigmatix(dot)net
Subject: Re: Delegating superuser tasks to new security roles
Date: 2021-06-15 01:40:27
Message-ID: b33562ebaee67c25a2eff8def1beb136@oss.nttdata.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 2021-06-14 23:53, Mark Dilger wrote:
>> On Jun 14, 2021, at 5:51 AM, torikoshia <torikoshia(at)oss(dot)nttdata(dot)com>
>> wrote:
>>
>> Thanks for working on this topic, I appreciate it!
>
> Thank you for taking a look!
>
>> BTW, do these patches enable non-superusers to create user with
>> bypassrls?
>
> No, I did not break out the ability to create such users.
>
>> Since I failed to apply the patches and didn't test them,
>> I may have overlooked something but I didn't find the
>> corresponding codes.
>
> Do you believe that functionality should be added? I have not thought
> much about that issue.

I just noticed that because I was looking into operations that can only
be done by superusers.

It might be somewhat inconvenient in PostgreSQL service providers that
don't give users superuser privileges, but at least I don't have a
specific demand for it.

Regards,

--
Atsushi Torikoshi
NTT DATA CORPORATION

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Justin Pryzby 2021-06-15 01:42:08 Re: Different compression methods for FPI
Previous Message Kyotaro Horiguchi 2021-06-15 01:36:41 Re: Duplicate history file?