Skip to content

Commit 84387fc

Browse files
committed
doc: Add note about lack of publication privileges
This gives some additional advice on using row filters and column lists on publications securely. Author: Antonin Houska <ah@cybertec.at> Reviewed-by: Euler Taveira <euler@eulerto.com> Discussion: https://www.postgresql.org/message-id/flat/20330.1652105397@antos
1 parent 2ea5de2 commit 84387fc

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

doc/src/sgml/logical-replication.sgml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1570,6 +1570,17 @@ CONTEXT: processing remote data for replication origin "pg_16395" during "INSER
15701570
schema automatically, the user must be a superuser.
15711571
</para>
15721572

1573+
<para>
1574+
There are currently no privileges on publications. Any subscription (that
1575+
is able to connect) can access any publication. Thus, if you intend to
1576+
hide some information from particular subscribers, such as by using row
1577+
filters or column lists, or by not adding the whole table to the
1578+
publication, be aware that other publications in the same database could
1579+
expose the same information. Publication privileges might be added to
1580+
<productname>PostgreSQL</productname> in the future to allow for
1581+
finer-grained access control.
1582+
</para>
1583+
15731584
<para>
15741585
To create a subscription, the user must be a superuser.
15751586
</para>

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy