From: Laurenz Albe <laurenz.albe@cybertec.at>
To: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Patrick Stählin <me@packi.ch>
Cc: pgsql-docs@lists.postgresql.org
Subject: Re: Add sentence about SECURITY LABEL object ownership
Date: Thu, 05 Jun 2025 20:18:02 -0500
Message-ID: <199dfdd7fdea9ac1d654442dd154f3ef6f6db51d.camel@cybertec.at> (raw)
In-Reply-To: <1284778.1749136742@sss.pgh.pa.us>
References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch>
<2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at>
<1284778.1749136742@sss.pgh.pa.us>
On Thu, 2025-06-05 at 11:19 -0400, Tom Lane wrote:
> Laurenz Albe <laurenz.albe@cybertec.at> writes:
> > On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> > > I noticed that we don't document that you need to own the object being
> > > modified by SECURITY LABEL.
>
> Yeah, clearly a documentation oversight.
>
> > Wouldn't it be more accurate to say that you have to be a member of the owning role?
> > But perhaps that would be complicated enough to confuse many users.
> > In general, +1 for documenting that.
>
> Our standard boilerplate for this is, eg,
>
> You must own the table to use <command>ALTER TABLE</command>.
>
> I don't see a reason to do it differently here.
Objection withdrawn.
Yours,
Laurenz Albe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-docs@postgresql.org
Cc: laurenz.albe@cybertec.at, tgl@sss.pgh.pa.us, me@packi.ch, pgsql-docs@lists.postgresql.org
Subject: Re: Add sentence about SECURITY LABEL object ownership
In-Reply-To: <199dfdd7fdea9ac1d654442dd154f3ef6f6db51d.camel@cybertec.at>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox