of having no password.
<!--
-$PostgreSQL: pgsql/doc/src/sgml/ref/create_role.sgml,v 1.5 2005/12/18 02:17:16 petere Exp $
+$PostgreSQL: pgsql/doc/src/sgml/ref/create_role.sgml,v 1.6 2005/12/23 16:46:39 petere Exp $
PostgreSQL documentation
-->
<listitem>
<para>
Sets the role's password. (A password is only of use for
- roles having the <literal>LOGIN</literal> attribute, but you can
- nonetheless define one for roles without it.)
- If you do not plan to use password
- authentication you can omit this option.
+ roles having the <literal>LOGIN</literal> attribute, but you
+ can nonetheless define one for roles without it.) If you do
+ not plan to use password authentication you can omit this
+ option. If no password is specified, the password will be set
+ to null and password authentication will always fail for that
+ user. A null password can optionally be written explicitly as
+ <literal>PASSWORD NULL</literal>.
</para>
</listitem>
</varlistentry>
* Portions Copyright (c) 1996-2005, PostgreSQL Global Development Group
* Portions Copyright (c) 1994, Regents of the University of California
*
- * $PostgreSQL: pgsql/src/backend/commands/user.c,v 1.166 2005/11/22 18:17:09 momjian Exp $
+ * $PostgreSQL: pgsql/src/backend/commands/user.c,v 1.167 2005/12/23 16:46:39 petere Exp $
*
*-------------------------------------------------------------------------
*/
defel->defname);
}
- if (dpassword)
+ if (dpassword && dpassword->arg)
password = strVal(dpassword->arg);
if (dissuper)
issuper = intVal(dissuper->arg) != 0;
defel->defname);
}
- if (dpassword)
+ if (dpassword && dpassword->arg)
password = strVal(dpassword->arg);
if (dissuper)
issuper = intVal(dissuper->arg);
!dconnlimit &&
!rolemembers &&
!validUntil &&
- password &&
+ dpassword &&
roleid == GetUserId()))
ereport(ERROR,
(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
new_record_repl[Anum_pg_authid_rolpassword - 1] = 'r';
}
+ /* unset password */
+ if (dpassword && dpassword->arg == NULL)
+ {
+ new_record_repl[Anum_pg_authid_rolpassword - 1] = 'r';
+ new_record_nulls[Anum_pg_authid_rolpassword - 1] = 'n';
+ }
+
/* valid until */
if (validUntil)
{
*
*
* IDENTIFICATION
- * $PostgreSQL: pgsql/src/backend/parser/gram.y,v 2.517 2005/12/11 10:54:27 neilc Exp $
+ * $PostgreSQL: pgsql/src/backend/parser/gram.y,v 2.518 2005/12/23 16:46:39 petere Exp $
*
* HISTORY
* AUTHOR DATE MAJOR EVENT
$$ = makeDefElem("password",
(Node *)makeString($2));
}
+ | PASSWORD NULL_P
+ {
+ $$ = makeDefElem("password", NULL);
+ }
| ENCRYPTED PASSWORD Sconst
{
$$ = makeDefElem("encryptedPassword",