Improve documentation of the CREATEROLE attibute.
authorRobert Haas <rhaas@postgresql.org>
Tue, 3 Jan 2023 19:50:40 +0000 (14:50 -0500)
committerRobert Haas <rhaas@postgresql.org>
Tue, 3 Jan 2023 19:57:40 +0000 (14:57 -0500)
commit5136c3fb575bb46f5f33c0485c972aa5dea0757a
tree6d45f5ffb6c5a76bc1f7fbac2b6cd6f896fecadb
parente373e5578bc39af4f20a4b70c5db1895d0e2d3d1
Improve documentation of the CREATEROLE attibute.

In user-manag.sgml, document precisely what privileges are conveyed
by CREATEROLE. Make particular note of the fact that it allows
changing passwords and granting access to high-privilege roles.
Also remove the suggestion of using a user with CREATEROLE and
CREATEDB instead of a superuser, as there is no real security
advantage to this approach.

Elsewhere in the documentation, adjust text that suggests that
<literal>CREATEROLE</literal> only allows for role creation, and
refer to the documentation in user-manag.sgml as appropriate.

Patch by me, reviewed by Álvaro Herrera

Discussion: http://postgr.es/m/CA+TgmoZBsPL8nPhvYecx7iGo5qpDRqa9k_AcaW1SbOjugAY1Ag@mail.gmail.com
doc/src/sgml/ref/alter_role.sgml
doc/src/sgml/ref/create_role.sgml
doc/src/sgml/ref/createuser.sgml
doc/src/sgml/user-manag.sgml