pgsql: Make psql's \password default to CURRENT_USER, not PQuser(conn). - Mailing list pgsql-committers

From Tom Lane
Subject pgsql: Make psql's \password default to CURRENT_USER, not PQuser(conn).
Date
Msg-id E1mlceY-0000yg-BT@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
Make psql's \password default to CURRENT_USER, not PQuser(conn).

The documentation says plainly that \password acts on "the current user"
by default.  What it actually acted on, or tried to, was the username
used to log into the current session.  This is not the same thing if
one has since done SET ROLE or SET SESSION AUTHENTICATION.  Aside from
the possible surprise factor, it's quite likely that the current role
doesn't have permissions to set the password of the original role.

To fix, use "SELECT CURRENT_USER" to get the role name to act on.
(This syntax works with servers at least back to 7.0.)  Also, in
hopes of reducing confusion, include the role name that will be
acted on in the password prompt.

The discrepancy from the documentation makes this a bug, so
back-patch to all supported branches.

Patch by me; thanks to Nathan Bossart for review.

Discussion: https://postgr.es/m/747443.1635536754@sss.pgh.pa.us

Branch
------
REL_10_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/3bc46e4e9d7a9da9a4cfa9795219509af79e93af

Modified Files
--------------
src/bin/psql/command.c | 34 +++++++++++++++++++++-------------
1 file changed, 21 insertions(+), 13 deletions(-)


pgsql-committers by date:

Previous
From: Tom Lane
Date:
Subject: Re: pgsql: Remove check for accept() argument types
Next
From: Daniel Gustafsson
Date:
Subject: pgsql: Document PG_TEST_NOCLEAN in TAP test README