On Wed, Feb 7, 2018 at 11:34 AM, Cory Nemelka <cnemelka@xxxxxxxxx> wrote:
this seems to be a security hole. this means I can see query text for queries that aren't mine. anyone else concerned?--cnemelkaOn Wed, Feb 7, 2018 at 10:17 AM, Shreeyansh Dba <shreeyansh2014@xxxxxxxxx> wrote:Hi Mark Steben,There is no superuser required to view pg_stat_activity, a normal user can also view or access.
I believe Shreeyansh is incorrect. You can view some fields as a normal user but you can't view query text (in addition to some others) unless you are superuser, or perhaps the new monitoring role in Pg10.
Don.
Don Seiler
www.seiler.us
www.seiler.us