pg.ddx.io  pgsql-docs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html
2+ messages / 2 participants
[nested] [flat]

* wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html
@ 2025-06-12 08:19 PG Doc comments form <noreply@postgresql.org>
  2025-06-12 13:15 ` Re: wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html Laurenz Albe <laurenz.albe@cybertec.at>
  0 siblings, 1 reply; 2+ messages in thread

From: PG Doc comments form @ 2025-06-12 08:19 UTC (permalink / raw)
  To: pgsql-docs@lists.postgresql.org; +Cc: o15611@gmail.com

The following documentation comment has been logged on the website:

Page: https://www.postgresql.org/docs/14/predefined-roles.html
Description:

Page: https://www.postgresql.org/docs/current/predefined-roles.html
Wrong statement: "Administrators (including roles that have the CREATEROLE
privilege) can GRANT these roles to users and/or other roles in their
environment, providing those users with access to the specified capabilities
and information."
Suggested statement: "SUPERUSER or roles granted with the ADMIN option on
the particular predifined roles can GRANT these roles other roles, providing
those users with access to the specified capabilities and information."
Testcase:
postgres=> create role bob;
CREATE ROLE
postgres=> grant pg_checkpoint to bob;
ERROR:  permission denied to grant role "pg_checkpoint"
DETAIL:  Only roles with the ADMIN option on role "pg_checkpoint" may grant
this role.
postgres=> grant pg_create_subscription to bob;
ERROR:  permission denied to grant role "pg_create_subscription"
DETAIL:  Only roles with the ADMIN option on role "pg_create_subscription"
may grant this role.


^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html
  2025-06-12 08:19 wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html PG Doc comments form <noreply@postgresql.org>
@ 2025-06-12 13:15 ` Laurenz Albe <laurenz.albe@cybertec.at>
  0 siblings, 0 replies; 2+ messages in thread

From: Laurenz Albe @ 2025-06-12 13:15 UTC (permalink / raw)
  To: o15611@gmail.com; pgsql-docs@lists.postgresql.org

On Thu, 2025-06-12 at 08:19 +0000, PG Doc comments form wrote:
> The following documentation comment has been logged on the website:
> 
> Page: https://www.postgresql.org/docs/14/predefined-roles.html
> Description:
> 
> Page: https://www.postgresql.org/docs/current/predefined-roles.html
> Wrong statement: "Administrators (including roles that have the CREATEROLE
> privilege) can GRANT these roles to users and/or other roles in their
> environment, providing those users with access to the specified capabilities
> and information."
> Suggested statement: "SUPERUSER or roles granted with the ADMIN option on
> the particular predifined roles can GRANT these roles other roles, providing
> those users with access to the specified capabilities and information."
> Testcase:
> postgres=> create role bob;
> CREATE ROLE
> postgres=> grant pg_checkpoint to bob;
> ERROR:  permission denied to grant role "pg_checkpoint"
> DETAIL:  Only roles with the ADMIN option on role "pg_checkpoint" may grant
> this role.
> postgres=> grant pg_create_subscription to bob;
> ERROR:  permission denied to grant role "pg_create_subscription"
> DETAIL:  Only roles with the ADMIN option on role "pg_create_subscription"
> may grant this role.

+1

That looks like a clear oversight.

Yours,
Laurenz Albe





^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2025-06-12 13:15 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2025-06-12 08:19 wrong statement in the https://www.postgresql.org/docs/current/predefined-roles.html PG Doc comments form <noreply@postgresql.org>
2025-06-12 13:15 ` Laurenz Albe <laurenz.albe@cybertec.at>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox