Re: Recognizing superuser in pg_hba.conf

Stephen Frost <[email protected]>
Newsgroups gmane.comp.db.postgresql.devel.general
Message-ID <[email protected]>
Greetings,

* Robert Haas ([email protected]) wrote:
> But, again, we already *have* a way of solving this problem: use
> quotes. As Simon pointed out, your proposed solution isn't really a
> solution at all, because & can appear in role names. It probably
> won't, but there probably also won't be a role name that matches
> either of these keywords, so it's just six of one, half a dozen of the
> other. The thing that really solves it is quoting.

I really just can't agree with the idea that:

"&superuser"

and

&superuser

in pg_hba.conf should mean materially different things and have far
reaching security differences.  Depending on quoting in pg_hba.conf for
this distinction is an altogether bad idea.

> Now I admit that if we decide pg_hba.conf keywords have to start with
> "pg_" and prevent names beginning with "pg_" from being used as object
> names, then we'd have TWO ways of distinguishing between a keyword and
> an object name. But I don't think TMTOWTDI is the right design
> principle here.

There is a *really* big difference here though which makes this not "two
ways to do the same thing"- you *can't* create a user starting with
"pg_".  You *can* create a user with an '&' in it.  If we prevented you
from being able to create users with '&' in it then I'd be more open to
the idea of using '&' to mean something special in pg_hba, and then it
really would be two different ways to do the same thing, but that's not
actually what's being proposed here.

Thanks,

Stephen
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJeF1aVAAoJEO1sijiDR2RVi9gP/26X/cg/THN0ebOp6L248xM5
PXrQf/IoKUWi93gYm98GnnPyFKRb1r3Mb5mUT63X9bOSaUCS7YRbqheUiMeqh1fn
YF8o/x2+nYk+q90evZdidVW0sWysW82/gekDfvgf2yoGCVLf0bhi73+nrzwh8QfS
m0QtZ45nXQm9ZBMhUbg/1RkEhK2/OtxaFvE5S/8TPud1KQldv9pKQABsSho8CxrN
5Cihw6/segSjfG046FHLSDb+yiYUATbmTONtqCwQQuoiRrHttuCO3m+rmqH3YSLF
LY69Ku8DsDvlsGjQv9LlQ9vGDX3ebwCNjrMWxDWZ55nrHivV8bmd853ZJTGx9TEk
Cr7zeTJqkdSAHd3lwypqQwNdEaJBOK2dbBr9wbLWX4XCqLVYEJ4BwilKps6ZH4O3
Mf4DUoTiwwQ430TfWFrE3x7MwnFtBUdSXcCu91hdP2ptzvDNSw/2gWQdji4FN/fb
Ge7/nwDBa3hdYumxzuvSPXDfxlBab88TZarzd82OIhnYz3Bxj7dslsi8oTTvDfYQ
iv7/J+72KW3UopRwkmJfovmXjwRPmJPp+NQiVkiHjEq04Qb4GntRAoRmdG/tl/OM
PkZocZiAsnVKrf3vetEhyhxoROshjR3EdMnKMXuq/VO0sw0nz9s0mIqVAOxh5rdo
g1rgQN8OFSGKU6MvfnMd
=VwsN
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.