Re: connect permission based on database name
От | Rob Sargent |
---|---|
Тема | Re: connect permission based on database name |
Дата | |
Msg-id | cb6ebae1-2ee9-df60-54b7-00d0f4810850@gmail.com обсуждение исходный текст |
Ответ на | Re: connect permission based on database name (Tom Lane <tgl@sss.pgh.pa.us>) |
Ответы |
Re: connect permission based on database name
|
Список | pgsql-general |
On 5/25/22 08:20, Tom Lane wrote:
And then the search path is "just a string"?Rob Sargent <robjsargent@gmail.com> writes:Just wondering if I've bumped into some security issue. I'm somewhat surprised that "grant connect to database <dbname> to <role>" appears to be stored "by name"?I think you are forgetting that databases have a default GRANT CONNECT TO PUBLIC. You need to revoke that before other grants/revokes will have any functional effect. regards, tom lane
psql --user oldrole --dbname newdb --host $DBHOST
psql (12.11, server 12.7)
SSL connection (protocol: TLSv1.2, cipher: ECDHE-RSA-AES256-GCM-SHA384, bits: 256, compression: off)
Type "help" for help.
newdb=> show search_path;
search_path
--------------------
study, base, public
(1 row)
В списке pgsql-general по дате отправления: