Re: prevent users from SELECT-ing from pg_roles/pg_database

From: Laurenz Albe <laurenz(dot)albe(at)cybertec(dot)at>
To: Andreas Joseph Krogh <andreas(at)visena(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: pgsql-general(at)lists(dot)postgresql(dot)org
Subject: Re: prevent users from SELECT-ing from pg_roles/pg_database
Date: 2024-05-27 09:10:10
Message-ID: bd7905e2e1a920fb5ed3b8fa9ab0d7c8e8f2b52d.camel@cybertec.at
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Mon, 2024-05-27 at 09:33 +0200, Andreas Joseph Krogh wrote:
> I tried:
>
> REVOKE SELECT ON pg_catalog.pg_database FROM public;
>
> But that doesn't prevent a normal user from querying pg_database it seems…

It works here.

Perhaps the "normal" user is a member of "pg_read_all_data".

Yours,
Laurenz Albe

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Laurenz Albe 2024-05-27 09:20:29 Re: Long running query causing XID limit breach
Previous Message Andreas Joseph Krogh 2024-05-27 07:33:51 Re: prevent users from SELECT-ing from pg_roles/pg_database