Re: Bug #931: bugs "create user" "alter user" - Mailing list pgsql-bugs

From Stephan Szabo
Subject Re: Bug #931: bugs "create user" "alter user"
Date
Msg-id 20030403074710.H79234-100000@megazone23.bigpanda.com
Whole thread Raw
In response to Bug #931: bugs "create user" "alter user"  (pgsql-bugs@postgresql.org)
List pgsql-bugs
On Thu, 3 Apr 2003 pgsql-bugs@postgresql.org wrote:

> techi (snieznik@interia.pl) reports a bug with a severity of 2
> The lower the number the more severe it is.

>  (FIRST METHOD)
>      CREATE USER Michael ;    or CREATE DATABASE school  ;
>      The output is for both commands : PERMISSION DENIED
>             and that's ok.
>
>       BUT when I as a superuser create a new user called "Paul" with
>       command
>    (SECOND METHOD)
>        CREATE USER Paul WITH NOCREATEDB NOCREATEUSER ;
>        The output is CREATE USER .
>        and here is a bug .
>          When I am logged to psql as a new user techi and I am trying
>          to create a database or create user ---- and unfortunatelly
>          it is working .
>          Paul is allowed to create a new user acount and a new
>          database but he couldn't do it !!!!!!!!!!!!!

I'm not sure what you're saying here. Are you saying that paul was
allowed and techi wasn't and both were created the same way?

>           ALTER USER Robert WITH CREATEUSER ;
>           The output is ok .
>           But something goes wrong , the user Rober is also allowed to
>           create a database!!!!!!!!!!! he shouldn't do it !!!!!!!

I think createuser implies superuser access currently so nocreatedb is
trumped by that.  The man page in current version seems to say that for
ALTER USER (although the text is kind of poor).

pgsql-bugs by date:

Previous
From: Tom Lane
Date:
Subject: Re: Delete triggers
Next
From: "Tony Harper"
Date:
Subject: RelationBuildDesc Notice