Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uD2ha-005jja-DH for pgsql-docs@arkaria.postgresql.org; Thu, 08 May 2025 14:58:22 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1uD2hY-004HFA-MX for pgsql-docs@arkaria.postgresql.org; Thu, 08 May 2025 14:58:20 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uD2hY-004HEy-Eu for pgsql-docs@lists.postgresql.org; Thu, 08 May 2025 14:58:20 +0000 Received: from mail-ed1-x532.google.com ([2a00:1450:4864:20::532]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1uD2hU-000qYl-2y for pgsql-docs@lists.postgresql.org; Thu, 08 May 2025 14:58:19 +0000 Received: by mail-ed1-x532.google.com with SMTP id 4fb4d7f45d1cf-5fbc736f0c7so1587029a12.2 for ; Thu, 08 May 2025 07:58:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1746716294; x=1747321094; darn=lists.postgresql.org; h=message-id:in-reply-to:to:references:date:subject:mime-version :content-transfer-encoding:from:from:to:cc:subject:date:message-id :reply-to; bh=HKEfV+DrtyrQJq14KIoxtOp0a+GrcMnROZI3wHN6ya0=; b=HBZlmuxO/KDPSqmIG4B5BhmakyKwe8JIAWZeyPwJ/PuFZnDdn1CaRTkU97G5OC0m2S YGVHm7fZ+VtoefycYANvNVTIUM4tjqfKyDELiaZbkN7+wad60RAsPskrSeV5lgy6iye6 lypj9lxbXRkmIzEQ6P8mTNu2hGQkaX7OmOCyqoZFTNUXW6M5fOU4ooEKajLw4uRf2G4m u/y43zZr/DMJWIcTOlv6rZlWf9qhNLGuee9lTTT252ZcYHBRyPam57t6eQIbfX8ePK30 a/lxovMA0fDYMUzEd6yofevlbAiJ1DgBeEQ8HTawXHJ1N9Ecgb0ILoBCMcPJM726iYK7 hglQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1746716294; x=1747321094; h=message-id:in-reply-to:to:references:date:subject:mime-version :content-transfer-encoding:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=HKEfV+DrtyrQJq14KIoxtOp0a+GrcMnROZI3wHN6ya0=; b=HsbX0r6Hi64Rem85yJQC3DzuGyc/ILNKCVGBAHMIhlh4EnwU9V1rrJalz0jCG10xHP yXVqGadXbobOBubdGU1u6oRXiMbT5IfYluyv0CwEwRCx/uNNKUxn2SZT4d5DMBFI7SxE QQo7QNlrbWWkcDkqd/dB8KUNwXsT+KQq7XYe/nLErbbwsqPn+oteShVBG1SwJV8BCWye doUChzbvGn1J40IDjp5HrdNSgTpYVwb1FfCyJL/niyqX5b1ZLRSB+dQ1RJsiG514JEI5 S3AzfnQaP3LoU2BojwSZjrBK4tIa8REsZvYLsW6Hgb3YmWiFD/nh/YOMgnWlB1xcbIKQ kM6A== X-Gm-Message-State: AOJu0YwrdlqJ6wKRyTh/6wj22ApQ9QYnHF1PDSQUAJY8gE+1VQpbiGsY b8YCU6xYAGj2zdCSPimghvf8kTCFv141ljn/DdP9ZttqCeoxt2ckD9Zvhx1O X-Gm-Gg: ASbGncsRAKx2WBd+IBKhuzsWY9J2KhnvdZ5v9CbWCEFAzF0L/R6f4B9xItWpHL03GFT JC2UgeiAuIELtuHxrOkewET2CYZMm/fThnSnIVQxeh0Czwj+MzBEag+KiaayEzwr5aX5YH7dWyv jcC2khRwDZYomtejW+03S/s0kZJPsoq2DcXexOQPD1pDnE4hOTO7/asg5ztXhI/229gz4NNO1TZ 3ZOvLlOWWXrB+G20vmPpDzdSQ7+M4GjjPXE0vCTyjRCHLmgoeRQq/qGFqqb6wzSn+CuPVDf9k8p FRyGi6swzqfxnE80Hm06/uWnob+XI/l2fGCesqhQ96mgXJPCil2JZEhD84b4ACz5tg== X-Google-Smtp-Source: AGHT+IFW2b8teoOAyj4yy55aLCEHZ3RqcRVHjOSdZpt5M7O+h9nDQ0qSKANKz0/RPtvmCkTE9kkHCA== X-Received: by 2002:a05:6402:350d:b0:5f6:218d:34f3 with SMTP id 4fb4d7f45d1cf-5fc35a2d2e7mr3465200a12.28.1746716293772; Thu, 08 May 2025 07:58:13 -0700 (PDT) Received: from smtpclient.apple ([79.127.241.70]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-5fc9bf9d4c4sm1111a12.0.2025.05.08.07.58.12 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 08 May 2025 07:58:12 -0700 (PDT) From: Andrei Polushin Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.500.181.1.5\)) Subject: "GRANT on Roles" supports multiple options Date: Thu, 8 May 2025 21:58:11 +0700 References: <174671599514.1455381.16053182845970432387@wrigleys.postgresql.org> To: pgsql-docs@lists.postgresql.org In-Reply-To: <174671599514.1455381.16053182845970432387@wrigleys.postgresql.org> Message-Id: X-Mailer: Apple Mail (2.3826.500.181.1.5) List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk (resending with correct formatting) Hi! In the documentation of the GRANT[1] command, the Synopsis for "GRANT on = Roles" command is incomplete. Quoting from the current docs: GRANT role_name [, ...] TO role_specification [, ...] [ WITH { ADMIN | INHERIT | SET } { OPTION | TRUE | FALSE } ] [ GRANTED BY role_specification ] The "GRANT on Roles" command is documented as if it expects a single = option after "WITH", but it actually supports multiple options, = separated by comma, e.g. GRANT created_user TO creating_user WITH ADMIN TRUE, SET FALSE, = INHERIT FALSE The example is taken from section "21.2. Role Attributes"[2] of the = documentation. More examples can be found by searching the codebase: git grep -Pi '\bGRANT\b.+\bTO\b.+,\s*(ADMIN|INHERIT|SET)\s+\w+' The parser is implemented here: src/backend/commands/user.c:1480:GrantRole(ParseState *pstate, = GrantRoleStmt *stmt) The documentation is to be corrected for v16, v17, and later versions. [1]: https://www.postgresql.org/docs/17/sql-grant.html [2]: https://www.postgresql.org/docs/17/role-attributes.html diff --git a/doc/src/sgml/ref/grant.sgml b/doc/src/sgml/ref/grant.sgml index 999f657d5c0..9796e9a49d7 100644 --- a/doc/src/sgml/ref/grant.sgml +++ b/doc/src/sgml/ref/grant.sgml @@ -100,3 +100,3 @@ GRANT { USAGE | ALL [ PRIVILEGES ] } GRANT role_name [, ...] = TO role_specification [, = ...] - [ WITH { ADMIN | INHERIT | SET } { OPTION | TRUE | FALSE } ] + [ WITH [ { ADMIN | INHERIT | SET } { OPTION | TRUE | FALSE } ] [, = ...] ] [ GRANTED BY role_specification ] -- Andrei Polushin