privilege shedding - Mailing list pgsql-admin

From dkeeney
Subject privilege shedding
Date
Msg-id b6680ffd-0b5e-456d-9f8a-164acdc5260c@m44g2000hsc.googlegroups.com
Whole thread Raw
Responses Re: privilege shedding  ("Kevin Grittner" <Kevin.Grittner@wicourts.gov>)
List pgsql-admin
Is there a way to non-reversibly shed privilige within a PostgreSQL
session?

I would like to start a session as a superuser role, set up some views
and triggers as superuser, and then change role to a lesser role for
the remainder of the session.

It seems that if you use 'set role' for this, you get the lesser role,
but the original (superuser) role can be restored by another 'set
role' statement, without any re-authentication.  I would like the role
change to persist through the life of the session, without the option
of restoring the superuser role.


Thank you,
David

pgsql-admin by date:

Previous
From: "Albe Laurenz"
Date:
Subject: Re: [GENERAL] Regarding access to a user
Next
From: "slamp slamp"
Date:
Subject: Re: pg_log directory