Superuser without pg_hba could drop database - Mailing list pgadmin-support

From Mudy Situmorang
Subject Superuser without pg_hba could drop database
Date
Msg-id AANLkTikhq7YUXx0ex8eSZ59Y_+M0atJFTUJqcmUw8wAA@mail.gmail.com
Whole thread Raw
Responses Re: Superuser without pg_hba could drop database  (Guillaume Lelarge <guillaume@lelarge.info>)
List pgadmin-support
Superuser without pg_hba could drop database from client at pgAdminIII Object browser by left click & Delete/Drop. 

User has superuser rights, but no pg_hba connection entry for the host.

There are warnings on left click, twice:
An error has occured:
FATAL: no pg_hba.conf entry for host "172.17.0.8", user "tempuser", database "testdatabase", SSL on
FATAL: no pg_hba.conf entry for host "172.17.0.8", user "tempuser", database "testdatabase", SSL off

Then context menu appear, click Delete/Drop, Yes on confirmation. 

The database is gone.


pgAdminIII at client:
Windows XP
pgAdminIII 1.10.3 (from PostgreSQL 8.4 windows package)


PostgreSQL 8.4 server:
Ubuntu 10.04



I think it is very dangerous.

Regards,
Mudy


pgadmin-support by date:

Previous
From: Michael Shapiro
Date:
Subject: Re: Bug with exceptionally long values.
Next
From: Guillaume Lelarge
Date:
Subject: Re: Superuser without pg_hba could drop database