agora inbox for pgsql-docs@postgresql.org
help / color / mirror / Atom feedFrom: Laurenz Albe <laurenz.albe@cybertec.at>
To: Patrick Stählin <me@packi.ch>
To: pgsql-docs@lists.postgresql.org
Subject: Re: Add sentence about SECURITY LABEL object ownership
Date: Thu, 05 Jun 2025 09:21:47 -0500
Message-ID: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> (raw)
In-Reply-To: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch>
References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch>
On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> Hi,
>
> I noticed that we don't document that you need to own the object being
> modified by SECURITY LABEL.
>
> Page: https://www.postgresql.org/docs/current/sql-security-label.html
>
> I've attached a patch that would have answered that question (for me)
> without diving into the code.
> --- a/doc/src/sgml/ref/security_label.sgml
> +++ b/doc/src/sgml/ref/security_label.sgml
> @@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
> based on object labels, rather than traditional discretionary access control
> (DAC) concepts such as users and groups.
> </para>
> +
> + <para>
> + You must own the database object to use the <command>SECURITY LABEL</command>.
> + </para>
> </refsect1>
>
> <refsect1>
Wouldn't it be more accurate to say that you have to be a member of the owning role?
But perhaps that would be complicated enough to confuse many users.
In general, +1 for documenting that.
Yours,
Laurenz Albe
view thread (5+ messages) latest in thread
Message-ID: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at>
Permalink: ../2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at/
Also on: postgresql.org/message-id/2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-docs@postgresql.org
Cc: laurenz.albe@cybertec.at, me@packi.ch, pgsql-docs@lists.postgresql.org
Subject: Re: Add sentence about SECURITY LABEL object ownership
In-Reply-To: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox