| Server IP : 88.99.149.37 / Your IP : 216.73.216.141 Web Server : nginx/1.31.2 System : Linux server-88-99-149-37 6.12.0-124.56.5.el10_1.x86_64 #1 SMP PREEMPT_DYNAMIC Fri May 15 06:12:08 EDT 2026 x86_64 User : muralimurth ( 1015) PHP Version : 8.4.23 Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : ON Directory : /usr/pgsql-17/share/man/man3/ |
Upload File : |
'\" t .\" Title: dblink_connect_u .\" Author: The PostgreSQL Global Development Group .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/> .\" Date: 2026 .\" Manual: PostgreSQL 17.10 Documentation .\" Source: PostgreSQL 17.10 .\" Language: English .\" .TH "DBLINK_CONNECT_U" "3" "2026" "PostgreSQL 17.10" "PostgreSQL 17.10 Documentation" .\" ----------------------------------------------------------------- .\" * Define some portability stuff .\" ----------------------------------------------------------------- .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .\" http://bugs.debian.org/507673 .\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" ----------------------------------------------------------------- .\" * set default formatting .\" ----------------------------------------------------------------- .\" disable hyphenation .nh .\" disable justification (adjust text to left margin only) .ad l .\" ----------------------------------------------------------------- .\" * MAIN CONTENT STARTS HERE * .\" ----------------------------------------------------------------- .SH "NAME" dblink_connect_u \- opens a persistent connection to a remote database, insecurely .SH "SYNOPSIS" .sp .nf dblink_connect_u(text connstr) returns text dblink_connect_u(text connname, text connstr) returns text .fi .SH "DESCRIPTION" .PP \fBdblink_connect_u()\fR is identical to \fBdblink_connect()\fR, except that it will allow non\-superusers to connect using any authentication method\&. .PP If the remote server selects an authentication method that does not involve a password, then impersonation and subsequent escalation of privileges can occur, because the session will appear to have originated from the user as which the local PostgreSQL server runs\&. Also, even if the remote server does demand a password, it is possible for the password to be supplied from the server environment, such as a ~/\&.pgpass file belonging to the server\*(Aqs user\&. This opens not only a risk of impersonation, but the possibility of exposing a password to an untrustworthy remote server\&. Therefore, \fBdblink_connect_u()\fR is initially installed with all privileges revoked from PUBLIC, making it un\-callable except by superusers\&. In some situations it may be appropriate to grant EXECUTE permission for \fBdblink_connect_u()\fR to specific users who are considered trustworthy, but this should be done with care\&. It is also recommended that any ~/\&.pgpass file belonging to the server\*(Aqs user \fInot\fR contain any records specifying a wildcard host name\&. .PP For further details see \fBdblink_connect()\fR\&.