agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
7+ messages / 1 participants
[nested] [flat]

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/17e805e8d8152db474bb368ab95cac127dfe6a4f

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/a649138d8558a97880d3ba1d1f41f66320debf7f

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/545e2a9d74c3ccca3189e56a515a5793b782eb9b

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/2b1054be851f6f601c4527d3814427b9aa4feb4e

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/cbf2779e70bd18eaab0ccd2eea70bcf8edd37444

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_15_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0e69b44dc2c1d31b41d38c6c5c0ed5e29809a19b

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous.
@ 2026-07-20 18:08 Robert Haas <rhaas@postgresql.org>
  0 siblings, 0 replies; 7+ messages in thread

From: Robert Haas @ 2026-07-20 18:08 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

doc: Granting TRIGGER or REFERENCES on table is dangerous.

It's always been the case that granting these privileges to users that
you don't fully trust was a bad idea, but it hasn't always been
obvious to people reading the documentation that this is the case.
To prevent confusion, and also repeated reports to pgsql-security,
mention it explicitly.

Discussion: http://postgr.es/m/CA+TgmobrjCHBuWHrvX3=2vndUCO2thUOdevrCcMDFW86cqCYvw@mail.gmail.com
Reviewed-by: Nathan Bossart <nathandbossart@gmail.com>
Backpatch-through: 14

Branch
------
REL_14_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/665bf40a132a857f1790de2aebffb14f85da7b6a

Modified Files
--------------
doc/src/sgml/ddl.sgml | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)



^ permalink  raw  reply  [nested|flat] 7+ messages in thread


end of thread, other threads:[~2026-07-20 18:08 UTC | newest]

Thread overview: 7+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>
2026-07-20 18:08 pgsql: doc: Granting TRIGGER or REFERENCES on table is dangerous. Robert Haas <rhaas@postgresql.org>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox