pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。
pg_authid #目录pg_authid包含关于数据库授权标识符(角色)的信息。角色涵盖了“用户”和“组”这两个概念。用户本质上只是设置了rolcanlogin标志的角色。任何角色(无论是否设置了rolcanlogin)都可以拥有其他角色作为成员;参见pg_auth_members。
由于这个目录包含密码,它不应公开可读。pg_roles是建立在pg_authid之上的公开可读视图,它会隐藏密码字段。
第 20 章包含关于用户和权限管理的详细信息。
由于用户标识符是集簇范围的,pg_authid在一个集簇的所有数据库之间共享:在一个集簇中只有一份pg_authid拷贝,而不是每个数据库一份。
表 45.8. pg_authid 列
| Name | Type | Description |
|---|---|---|
rolname |
name |
Role name |
rolsuper |
bool |
Role has superuser privileges |
rolinherit |
bool |
Role automatically inherits privileges of roles it is a member of |
rolcreaterole |
bool |
Role can create more roles |
rolcreatedb |
bool |
Role can create databases |
rolcatupdate |
bool |
Role can update system catalogs directly. (Even a superuser cannot do this unless this column is true) |
rolcanlogin |
bool |
Role can log in. That is, this role can be given as the initial session authorization identifier |
rolreplication |
bool |
Role is a replication role. That is, this role can initiate streaming replication (see 第 25.2.5 节) and set/unset the system backup mode using pg_start_backup and pg_stop_backup |
rolconnlimit |
int4 |
For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit. |
rolpassword |
text |
Password (possibly encrypted); null if none. If the password is encrypted, this column will begin with the string md5 followed by a 32-character hexadecimal MD5 hash. The MD5 hash will be of the user's password concatenated to their user name. For example, if user joe has password xyzzy, PostgreSQL will store the md5 hash of xyzzyjoe. A password that does not follow that format is assumed to be unencrypted. |
rolvaliduntil |
timestamptz |
Password expiry time (only used for password authentication); null if no expiration |
译文有误、术语不当或页面显示问题,请到译文仓库 pgsty/pgdoc 报告译文问题。 英文原文本身的问题,请在当前版本的对应页面向上游反馈;上游不再修订已结束维护的版本。