[WIP] Document update for Logical Replication security

Started by Shinoda, Noriyoshi (PN Japan FSIP)over 8 years ago2 messageshackers
Beta feature

Hackorum builds and tests every patch posted to the lists, not only commitfest submissions. This is Hackorum's own CI rather than the PostgreSQL project's, and it is still under testing - please report anything that looks wrong.

won't retrysuccessCI history

You can run a PostgreSQL built from this patch straight from Docker, with no checkout and no build:

docker run --rm -p 5432:5432 ghcr.io/hackorum-dev/postgres-patch:t38319
psql -h localhost -U postgres

Built from patchset v1 (message #1), July 27, 2026 at 09:01 PM.

Every patchset is also pushed to a branch of our PostgreSQL fork, so you can check out the same tree CI built. Without a PostgreSQL checkout:

git clone --branch t38319_1 https://github.com/hackorum-dev/postgres.git

In a checkout you already have, add the fork once:

git remote add hackorum https://github.com/hackorum-dev/postgres.git

then, for this patchset and every later one:

git fetch hackorum t38319_1 && git checkout t38319_1

Patchset v1 (message #1) is on t38319_1

Jump to latest
#1Shinoda, Noriyoshi (PN Japan FSIP)
noriyoshi.shinoda@hpe.com

Hi, Hackers,

The attached patch adds the following information to the document on Logical Replication.
About the requirement of connection role of Logical Replication, written in 31.7 of the manual is as follows.
--
The role used for the replication connection must have the REPLICATION attribute.
--
However, the Logical Replication connection role also requires the LOGIN attribute.
And, for initial snapshots of Logical Replication, the connection role requires SELECT privilege on the replication target table, but it is not described in the manual.

Regards,

Noriyoshi Shinoda

Attachments:

t38319_1
logical_replication_doc.patchapplication/octet-stream; name=logical_replication_doc.patchDownload+2-1
#2Peter Eisentraut
peter_e@gmx.net
In reply to: Shinoda, Noriyoshi (PN Japan FSIP) (#1)
Re: [WIP] Document update for Logical Replication security

On 3/3/18 07:35, Shinoda, Noriyoshi wrote:

Hi, Hackers,

The attached patch adds the following information to the document on Logical Replication.
About the requirement of connection role of Logical Replication, written in 31.7 of the manual is as follows.
--
The role used for the replication connection must have the REPLICATION attribute.
--
However, the Logical Replication connection role also requires the LOGIN attribute.
And, for initial snapshots of Logical Replication, the connection role requires SELECT privilege on the replication target table, but it is not described in the manual.

Committed, thanks.

--
Peter Eisentraut http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services