summaryrefslogtreecommitdiff
path: root/doc/src/sgml/ref/create_user_mapping.sgml
diff options
context:
space:
mode:
authorPeter Eisentraut <peter_e@gmx.net>2009-01-20 09:10:20 +0000
committerPeter Eisentraut <peter_e@gmx.net>2009-01-20 09:10:20 +0000
commit93a6be63a55a8cd0d73b3fa81eb6a46013a3a974 (patch)
tree687e12b06f610c10bd3acf2210275fbeb7cdfb84 /doc/src/sgml/ref/create_user_mapping.sgml
parentfe626982182bd1c8cd2606027a4d49a2f31a01c3 (diff)
Revise the permission checking on user mapping DDL commands.
CREATE/ALTER/DROP USER MAPPING are now allowed either by the server owner or by a user with USAGE privileges for his own user name. This is more or less what the SQL standard wants anyway (plus "implementation-defined") Hide information_schema.user_mapping_options.option_value, unless the current user is the one associated with the user mapping, or is the server owner and the mapping is for PUBLIC, or is a superuser. This is to protect passwords. Also, fix a bug in information_schema._pg_foreign_servers, which hid servers using wrappers where the current user did not have privileges on the wrapper. The correct behavior is to hide servers where the current user has no privileges on the server.
Diffstat (limited to 'doc/src/sgml/ref/create_user_mapping.sgml')
-rw-r--r--doc/src/sgml/ref/create_user_mapping.sgml11
1 files changed, 8 insertions, 3 deletions
diff --git a/doc/src/sgml/ref/create_user_mapping.sgml b/doc/src/sgml/ref/create_user_mapping.sgml
index b0589817492..6857b3eb7e9 100644
--- a/doc/src/sgml/ref/create_user_mapping.sgml
+++ b/doc/src/sgml/ref/create_user_mapping.sgml
@@ -1,5 +1,5 @@
<!--
-$PostgreSQL: pgsql/doc/src/sgml/ref/create_user_mapping.sgml,v 1.2 2009/01/17 04:24:41 neilc Exp $
+$PostgreSQL: pgsql/doc/src/sgml/ref/create_user_mapping.sgml,v 1.3 2009/01/20 09:10:20 petere Exp $
PostgreSQL documentation
-->
@@ -31,10 +31,15 @@ CREATE USER MAPPING FOR { <replaceable class="parameter">username</replaceable>
<para>
<command>CREATE USER MAPPING</command> defines a mapping of a user
- to a foreign server. You must be the owner of the server to define
- user mappings for it.
+ to a foreign server.
</para>
+ <para>
+ The owner of a foreign server can create user mappings for that
+ server for any user. Also, a user can create a user mapping for
+ his own user name if <literal>USAGE</> privilege on the server has
+ been granted to the user.
+ </para>
</refsect1>
<refsect1>