These patches have been split off the now deprecated monolithic "Delegating 
superuser tasks to new security roles" thread at [1].

The purpose of these patches is to fix the CREATEROLE escalation attack vector 
misfeature.  (Not everyone will see CREATEROLE that way, but the perceived 
value of the patch set likely depends on how much you see CREATEROLE in that 
light.)

Attachment: v1-0001-Add-tests-of-the-CREATEROLE-attribute.patch
Description: Binary data

Attachment: v1-0002-Add-owners-to-roles.patch
Description: Binary data

Attachment: v1-0003-Give-role-owners-control-over-owned-roles.patch
Description: Binary data

Attachment: v1-0004-Restrict-power-granted-via-CREATEROLE.patch
Description: Binary data


[1] 
https://www.postgresql.org/message-id/flat/F9408A5A-B20B-42D2-9E7F-49CD3D1547BC%40enterprisedb.com
—
Mark Dilger
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company



Reply via email to