Improve documentation of the CREATEROLE attibute.
authorRobert Haas <rhaas@postgresql.org>
Tue, 3 Jan 2023 19:50:40 +0000 (14:50 -0500)
committerRobert Haas <rhaas@postgresql.org>
Tue, 3 Jan 2023 20:00:18 +0000 (15:00 -0500)
commit1c77873727dfd2e48ab2ece84d1fb1676e95f9a5
tree405537d4fdf07f3a972560c48363c47017583ae0
parent54afdcd6182af709cb0ab775c11b90decff166eb
Improve documentation of the CREATEROLE attibute.

In user-manag.sgml, document precisely what privileges are conveyed
by CREATEROLE. Make particular note of the fact that it allows
changing passwords and granting access to high-privilege roles.
Also remove the suggestion of using a user with CREATEROLE and
CREATEDB instead of a superuser, as there is no real security
advantage to this approach.

Elsewhere in the documentation, adjust text that suggests that
<literal>CREATEROLE</literal> only allows for role creation, and
refer to the documentation in user-manag.sgml as appropriate.

Patch by me, reviewed by Álvaro Herrera

Discussion: http://postgr.es/m/CA+TgmoZBsPL8nPhvYecx7iGo5qpDRqa9k_AcaW1SbOjugAY1Ag@mail.gmail.com
doc/src/sgml/ref/alter_role.sgml
doc/src/sgml/ref/create_role.sgml
doc/src/sgml/ref/createuser.sgml
doc/src/sgml/user-manag.sgml