Re: Non-superuser subscription owners - Mailing list pgsql-hackers

From Ronan Dunklau
Subject Re: Non-superuser subscription owners
Date
Msg-id 4682671.GXAFRqVoOG@aivenronan
Whole thread Raw
In response to Non-superuser subscription owners  (Mark Dilger <mark.dilger@enterprisedb.com>)
List pgsql-hackers
Le mercredi 20 octobre 2021, 20:40:39 CEST Mark Dilger a écrit :
> These patches have been split off the now deprecated monolithic "Delegating
> superuser tasks to new security roles" thread at [1].
>
> The purpose of these patches is to allow non-superuser subscription owners
> without risk of them overwriting tables they lack privilege to write
> directly. This both allows subscriptions to be managed by non-superusers,
> and protects servers with subscriptions from malicious activity on the
> publisher side.

Thank you Mark for splitting this.

This patch looks good to me, and provides both better security (by closing the
"dropping superuser role" loophole) and usefule features.


--
Ronan Dunklau





pgsql-hackers by date:

Previous
From: Ronan Dunklau
Date:
Subject: Re: pg_receivewal starting position
Next
From: Michael Paquier
Date:
Subject: Re: pg_receivewal starting position