privilege shedding

Поиск
Список
Период
Сортировка
От dkeeney
Тема privilege shedding
Дата
Msg-id b6680ffd-0b5e-456d-9f8a-164acdc5260c@m44g2000hsc.googlegroups.com
обсуждение исходный текст
Ответы Re: privilege shedding  ("Kevin Grittner" <Kevin.Grittner@wicourts.gov>)
Список pgsql-admin
Is there a way to non-reversibly shed privilige within a PostgreSQL
session?

I would like to start a session as a superuser role, set up some views
and triggers as superuser, and then change role to a lesser role for
the remainder of the session.

It seems that if you use 'set role' for this, you get the lesser role,
but the original (superuser) role can be restored by another 'set
role' statement, without any re-authentication.  I would like the role
change to persist through the life of the session, without the option
of restoring the superuser role.


Thank you,
David

В списке pgsql-admin по дате отправления:

Предыдущее
От: "Albe Laurenz"
Дата:
Сообщение: Re: [GENERAL] Regarding access to a user
Следующее
От: "slamp slamp"
Дата:
Сообщение: Re: pg_log directory