{"kind": "role", "major": "18", "item": {"slug": "pg_write_server_files", "name": "pg_write_server_files", "name_zh": "pg_write_server_files", "category": "Server files and programs", "summary": "pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions.", "aliases": [], "versions": {"11": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Default roles"}], "related": [], "release": {"ref": "PostgreSQL 11.22 Documentation", "label": "11.22", "major": "11", "channel": "historical", "revision": "13adc471db2c3719b872a5ccb9c6cb6a7dad2f2c080f8fe6cc5374c8d6828099"}, "sources": [{"url": "/docs/11/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 11.22 Documentation", "sha256": "13adc471db2c3719b872a5ccb9c6cb6a7dad2f2c080f8fe6cc5374c8d6828099"}, {"url": "https://www.postgresql.org/docs/11/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 11 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "12": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Default roles"}], "related": [], "release": {"ref": "PostgreSQL 12.22 Documentation", "label": "12.22", "major": "12", "channel": "historical", "revision": "993243a8e1f0496fe066e6ed6e39d0d04b3aa25115e168609a38316b7110bdad"}, "sources": [{"url": "/docs/12/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 12.22 Documentation", "sha256": "993243a8e1f0496fe066e6ed6e39d0d04b3aa25115e168609a38316b7110bdad"}, {"url": "https://www.postgresql.org/docs/12/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 12 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "13": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Default roles"}], "related": [], "release": {"ref": "PostgreSQL 13.23 Documentation", "label": "13.23", "major": "13", "channel": "historical", "revision": "fef5a8f24a15034fbb3fa45d81971d5d77ff79f2725386ec3d3c476fae935dd3"}, "sources": [{"url": "/docs/13/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 13.23 Documentation", "sha256": "fef5a8f24a15034fbb3fa45d81971d5d77ff79f2725386ec3d3c476fae935dd3"}, {"url": "https://www.postgresql.org/docs/13/default-roles.html#DEFAULT-ROLES-TABLE", "label": "PostgreSQL 13 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "14": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 14.24 Documentation", "label": "14.24", "major": "14", "channel": "stable", "revision": "c4f98c255865a7a07ab35932e3b23ce2ab575a70c0cd8d3194de646732680f44"}, "sources": [{"url": "/docs/14/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 14.24 Documentation", "sha256": "c4f98c255865a7a07ab35932e3b23ce2ab575a70c0cd8d3194de646732680f44"}, {"url": "https://www.postgresql.org/docs/14/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 14 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "15": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 15.19 Documentation", "label": "15.19", "major": "15", "channel": "stable", "revision": "043d217ec318b20df8710081386db7be2eacafc839eae7f0c12df2712955f55a"}, "sources": [{"url": "/docs/15/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 15.19 Documentation", "sha256": "043d217ec318b20df8710081386db7be2eacafc839eae7f0c12df2712955f55a"}, {"url": "https://www.postgresql.org/docs/15/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 15 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "16": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 16.15 Documentation", "label": "16.15", "major": "16", "channel": "stable", "revision": "8626abe19619170614b1adbddcf8a8b5c58983fa82b372312ed7da04b73593ea"}, "sources": [{"url": "/docs/16/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 16.15 Documentation", "sha256": "8626abe19619170614b1adbddcf8a8b5c58983fa82b372312ed7da04b73593ea"}, {"url": "https://www.postgresql.org/docs/16/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 16 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "17": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 17.11 Documentation", "label": "17.11", "major": "17", "channel": "stable", "revision": "64c01b6876124ed9b6190d7418108b81e2f35b6290b0562b8e4466a65e0eb603"}, "sources": [{"url": "/docs/17/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 17.11 Documentation", "sha256": "64c01b6876124ed9b6190d7418108b81e2f35b6290b0562b8e4466a65e0eb603"}, {"url": "https://www.postgresql.org/docs/17/predefined-roles.html#PREDEFINED-ROLES-TABLE", "label": "PostgreSQL 17 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["The pg_read_server_files , pg_write_server_files and pg_execute_server_program roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. As these roles are able to access any file on the server file system, they bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access, therefore great care should be taken when granting these roles to users."]}], "description": ["Allow writing to files in any location the database can access on the server with COPY and other file-access functions."]}, "18": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 18.6 Documentation", "label": "18.6", "major": "18", "channel": "stable", "revision": "b7ebd726e6017f55081b4034b96d6a3289ae7937a26adaf72e58b9a08e009c75"}, "sources": [{"url": "/docs/18/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 18.6 Documentation", "sha256": "b7ebd726e6017f55081b4034b96d6a3289ae7937a26adaf72e58b9a08e009c75"}, {"url": "https://www.postgresql.org/docs/18/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 18 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["These roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. They bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access. Therefore, great care should be taken when granting these roles to users."]}], "description": ["pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions."]}, "19": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 19beta4 Documentation", "label": "19beta4", "major": "19", "channel": "preview", "revision": "f758684af9560594d8d6fa264fa05b8d9437883c8999dc9a387cc4ed235fcbe6"}, "sources": [{"url": "/docs/19/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 19beta4 Documentation", "sha256": "f758684af9560594d8d6fa264fa05b8d9437883c8999dc9a387cc4ed235fcbe6"}, {"url": "https://www.postgresql.org/docs/19/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 19 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["These roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. They bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access. Therefore, great care should be taken when granting these roles to users."]}], "description": ["pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions."]}, "20": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 20devel Documentation", "label": "20devel", "major": "20", "channel": "devel", "revision": "6850783e0465f49a366ff444d6c3b5674ee11d2fc310d6fdaed5c84781e83ca7"}, "sources": [{"url": "/docs/devel/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 20devel Documentation", "sha256": "6850783e0465f49a366ff444d6c3b5674ee11d2fc310d6fdaed5c84781e83ca7"}, {"url": "https://www.postgresql.org/docs/devel/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL devel online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["These roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. They bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access. Therefore, great care should be taken when granting these roles to users."]}], "description": ["pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions."]}}, "content_hash": "8a8b425e462095f3a6023a014bb2c06b8e7c460595cc2b6f78035ca19ea15c45", "imported_at": "2026-09-27T09:57:59.067"}, "snapshot": {"facts": [{"label": "Name", "value": "pg_write_server_files"}, {"label": "Manual terminology", "value": "Predefined roles"}], "related": [], "release": {"ref": "PostgreSQL 18.6 Documentation", "label": "18.6", "major": "18", "channel": "stable", "revision": "b7ebd726e6017f55081b4034b96d6a3289ae7937a26adaf72e58b9a08e009c75"}, "sources": [{"url": "/docs/18/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 18.6 Documentation", "sha256": "b7ebd726e6017f55081b4034b96d6a3289ae7937a26adaf72e58b9a08e009c75"}, {"url": "https://www.postgresql.org/docs/18/predefined-roles.html#PREDEFINED-ROLE-PG-READ-SERVER-FILES", "label": "PostgreSQL 18 online manual"}], "sections": [{"title": "Privileges and scope", "paragraphs": ["These roles are intended to allow administrators to have trusted, but non-superuser, roles which are able to access files and run programs on the database server as the user the database runs as. They bypass all database-level permission checks when accessing files directly and they could be used to gain superuser-level access. Therefore, great care should be taken when granting these roles to users."]}], "description": ["pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions."]}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}