Re: Re: [BUGS] BUG #13694: Row Level Security by-passed with CREATEUSER permission

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Joe Conway <mail(at)joeconway(dot)com>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Andres Freund <andres(at)anarazel(dot)de>, justin(dot)catterson(at)sofiebio(dot)com, pgsql-hackers(at)postgreSQL(dot)org
Subject: Re: Re: [BUGS] BUG #13694: Row Level Security by-passed with CREATEUSER permission
Date: 2015-10-22 15:54:39
Message-ID: 20151022155439.GY3685@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs pgsql-hackers

* Joe Conway (mail(at)joeconway(dot)com) wrote:
> On 10/21/2015 12:46 PM, Tom Lane wrote:
> > Attached patch rips out CREATEUSER and NOCREATEUSER options lock, stock,
> > and barrel.
>
> Looks good to me.
>
> > Another possibility is to change them to actually mean CREATEROLE and
> > NOCREATEROLE. I think probably a clean break is better though.
>
>
> I think that would be too confusing. I'd rather see them go away ala
> your patch.

Agreed.

Thanks!

Stephen

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Tom Lane 2015-10-22 16:34:55 Re: Re: [BUGS] BUG #13694: Row Level Security by-passed with CREATEUSER permission
Previous Message postgresql.org 2015-10-22 10:52:31 BUG #13701: Spelling error in bgwriter_lru_multiplier comment

Browse pgsql-hackers by date

  From Date Subject
Next Message Fabien COELHO 2015-10-22 16:00:37 Re: checkpointer continuous flushing
Previous Message Fabien COELHO 2015-10-22 15:16:13 Re: pgbench throttling latency limit