Re: Streaming replication as a separate permissions - Mailing list pgsql-hackers

From Simon Riggs
Subject Re: Streaming replication as a separate permissions
Date
Msg-id 1293464739.1193.64083.camel@ebony
Whole thread Raw
In response to Re: Streaming replication as a separate permissions  (Magnus Hagander <magnus@hagander.net>)
Responses Re: Streaming replication as a separate permissions  (Magnus Hagander <magnus@hagander.net>)
List pgsql-hackers
On Mon, 2010-12-27 at 14:54 +0100, Magnus Hagander wrote:

> You will certainly be able to log into the standby with a superuser
> account, nobody is preventing that. This is about protecting the
> *master*. For example, from modifications made by a user who hacked
> the standby. 

The users for master and standby are identical, so if they have access
to the standby, they have access to the master. That's why we allow
replication to be specifically excluded by the pg_hba.conf.

So I don't see how this helps.

-- Simon Riggs           http://www.2ndQuadrant.com/books/PostgreSQL Development, 24x7 Support, Training and Services



pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Reduce lock levels for ADD and DROP COLUMN
Next
From: Simon Riggs
Date:
Subject: Re: Reduce lock levels for ADD and DROP COLUMN