{"kind": "auth", "major": "18", "item": {"slug": "trust", "name": "trust", "name_zh": "", "category": "Authentication and access control", "summary": "Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details.", "aliases": [], "content_hash": "c1a8057247e10cb1b4f40fa724331983500786da2290ac5acecea25ffbc39678", "versions": {"10": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/auth-methods.html#AUTH-TRUST", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34"}, {"url": "/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.3.1 for details."], "manual_html": "<div class=\"sect2\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\">20.3.1.\u00a0Trust Authentication</h3>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/10/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/10/auth-methods.html#AUTH-TRUST", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "11": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 11 English manual", "sha256": "255fe3640ed5b16b5a7becfde9cdcba5f9eba8224e1cd82b526eff223100c2ac"}, {"url": "/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication</h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/11/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/11/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "12": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 12 English manual", "sha256": "d4e9df6ed4a436bf78764fb8b5ab96d1884dfb336d7e29e43bbd6e68ea69c6a6"}, {"url": "/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication</h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/12/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/12/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "13": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 13 English manual", "sha256": "823340fbbeb1817a54ef6ea4ec39eb2a7b8771520375d96f192f2f48d6eee057"}, {"url": "/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication</h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/13/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/13/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "14": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 14 English manual", "sha256": "c519a8f635cc7ab511eea09e1caec97ecaa587f851cca013246fd7bac9032957"}, {"url": "/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 21.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.4.\u00a0Trust Authentication</h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/14/runtime-config-connection.html\" title=\"20.3.\u00a0Connections and Authentication\">Section\u00a020.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/14/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "15": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 15 English manual", "sha256": "fae57f28dbf6e997b71f55ae587f6a3cc185b2739d9324d57198b5da9be8f29f"}, {"url": "/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 21.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.4.\u00a0Trust Authentication</h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/15/runtime-config-connection.html\" title=\"20.3.\u00a0Connections and Authentication\">Section\u00a020.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/15/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "16": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 16 English manual", "sha256": "5b91f3453aa08ec72643e007a2aa2ab9a9c3276175a80f6ec62ec72850f2ea1f"}, {"url": "/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 21.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/16/runtime-config-connection.html\" title=\"20.3.\u00a0Connections and Authentication\">Section\u00a020.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/16/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "17": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 17 English manual", "sha256": "4477a685fc74033e7cd25616416e68fd7e702471d59d121835adcedb69acf6cf"}, {"url": "/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/17/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/17/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "18": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 18 English manual", "sha256": "e4c50d6f88b13feb2004634788c61e0f797ff2d5b1ab6bb86de30229cef38a87"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/18/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/18/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "19": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 19 English manual", "sha256": "89448a10c298d0d25937c099c61e896508cc0cbf0eb6c563cfcbcc9610516d87"}, {"url": "/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/19/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/19/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "20": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 20 English manual", "sha256": "5c288997397f92bf4bc0d7cf49fb034b3e2f3ea2a0da7f398888ffab14e4f7c2"}, {"url": "/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/devel/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/devel/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}}}, "snapshot": {"facts": [{"label": "Method", "value": "trust"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-trust.html", "path": "auth-trust.html", "label": "PostgreSQL 18 English manual", "sha256": "e4c50d6f88b13feb2004634788c61e0f797ff2d5b1ab6bb86de30229cef38a87"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "trust", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-TRUST\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.4.\u00a0Trust Authentication </h2>\n</div>\n</div>\n</div>\n<p>When <code class=\"literal\">trust</code> authentication is specified, <span class=\"productname\">PostgreSQL</span> assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the <code class=\"literal\">database</code> and <code class=\"literal\">user</code> columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.</p>\n<p><code class=\"literal\">trust</code> authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually <span class=\"emphasis\"><em>not</em></span> appropriate by itself on a multiuser machine. However, you might be able to use <code class=\"literal\">trust</code> even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the <code class=\"varname\">unix_socket_permissions</code> (and possibly <code class=\"varname\">unix_socket_group</code>) configuration parameters as described in <a class=\"xref\" href=\"/docs/18/runtime-config-connection.html\" title=\"19.3.\u00a0Connections and Authentication\">Section\u00a019.3</a>. Or you could set the <code class=\"varname\">unix_socket_directories</code> configuration parameter to place the socket file in a suitably restricted directory.</p>\n<p>Setting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the <code class=\"literal\">host ... 127.0.0.1 ...</code> line from <code class=\"filename\">pg_hba.conf</code>, or change it to a non-<code class=\"literal\">trust</code> authentication method.</p>\n<p><code class=\"literal\">trust</code> authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the <code class=\"filename\">pg_hba.conf</code> lines that specify <code class=\"literal\">trust</code>. It is seldom reasonable to use <code class=\"literal\">trust</code> for any TCP/IP connections other than those from <span class=\"systemitem\">localhost</span> (127.0.0.1).</p>\n</div>", "manual_path": "/docs/18/auth-trust.html", "comparison_data": {"method": "trust", "documented_option_names": []}, "comparison_hash": "210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}