Alvaro Herrera <alvherre(at)alvh(dot)no-ip(dot)org> writes:
> Could you just set the policy to be granted to "only the bootstrap
> superuser" in that case? I mean as an implementation path for back
> branches; use NONE going forward. That would make the policy allow
> nobody who can't already access the record, instead of falling back to
> PUBLIC -- which I agree seems suboptimal security-wise.
That doesn't seem like a great solution --- it would produce very
confusing output from pg_dump for instance. In fact, I think it
breaks pg_dump for cases where the target DB has a different
bootstrap superuser name.
regards, tom lane