On Tue, Jun 07, 2022 at 10:08:21PM +0900, Ian Lawrence Barwick wrote:
> A little late to the party, but as an alternative suggestion for the last
> part:
>
> "... and users who either own the session being reported on, or who have
> privileges of the role to which the session belongs,"
>
> so the whole sentence would read:
>
> Note that even when enabled, this information is only visible to superusers,
> roles with privileges of the pg_read_all_stats role, and users who either own
> the session being reported on or who have privileges of the role to which the
> session belongs, so it should not represent a security risk.
This seems clearer to me.
--
Nathan Bossart
Amazon Web Services: https://aws.amazon.com