Re: Removing a user's password - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Removing a user's password
Date
Msg-id 4307.1053974860@sss.pgh.pa.us
Whole thread Raw
In response to Re: Removing a user's password  (Bruce Momjian <pgman@candle.pha.pa.us>)
Responses Re: Removing a user's password
List pgsql-hackers
Bruce Momjian <pgman@candle.pha.pa.us> writes:
> Tom Lane wrote:
>> If you set VALID UNTIL to 'now' (or sometime in the past), you've
>> effectively prevented him from logging in with the password ---
>> more effectively than setting the password to NULL, since if the
>> user is still logged in he can just undo that.  I don't think we
>> really need to do anything more here.

> Well, can they undo the VALID UNTIL too?

No: a non-superuser can only set his password, not any other fields of
his pg_shadow entry.

> I think at a minimum we need
> to document the proper procedure for removing a password.  I see NULL as
> a more logical way of removing the password rather than playing with
> VALID UNTIL.

It may be more logical, but it doesn't work as well.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: Changing behavior of BEGIN...sleep...do something...COMMIT
Next
From: Bruce Momjian
Date:
Subject: Re: Removing a user's password