{"Entry":{"collection":"auth","key":"trust","name":"trust","aliases":[],"metadata":{"aliases":[],"category":"Authentication and access control","content_hash":"c1a8057247e10cb1b4f40fa724331983500786da2290ac5acecea25ffbc39678","imported_at":"2026-09-30T00:40:33.365828+08:00","name":"trust","name_zh":"","slug":"trust","summary":"Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."}},"Definition":{"Collection":"auth","Key":"trust","SourceDatabase":"center","Version":"18","SourceTable":"authentication_method","SourceKey":"trust","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"trust"},"comparison_data":{"documented_option_names":[],"method":"trust"},"comparison_hash":"210f7621166817effd2ba02b45ddaf7562e7926b1a9ef4c7e4145fb9c662d19e","description":["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."],"facts":[{"label":"Method","value":"trust"},{"label":"Configuration","value":"pg_hba.conf"},{"label":"Inventory","value":"User-visible source authentication method"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-TRUST\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.4. Trust Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eWhen \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is specified, \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the \u003ccode class=\"literal\"\u003edatabase\u003c/code\u003e and \u003ccode class=\"literal\"\u003euser\u003c/code\u003e columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually \u003cspan class=\"emphasis\"\u003e\u003cem\u003enot\u003c/em\u003e\u003c/span\u003e appropriate by itself on a multiuser machine. However, you might be able to use \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the \u003ccode class=\"varname\"\u003eunix_socket_permissions\u003c/code\u003e (and possibly \u003ccode class=\"varname\"\u003eunix_socket_group\u003c/code\u003e) configuration parameters as described in \u003ca class=\"xref\" href=\"/docs/18/runtime-config-connection.html\" title=\"19.3. Connections and Authentication\"\u003eSection 19.3\u003c/a\u003e. Or you could set the \u003ccode class=\"varname\"\u003eunix_socket_directories\u003c/code\u003e configuration parameter to place the socket file in a suitably restricted directory.\u003c/p\u003e\n\u003cp\u003eSetting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the \u003ccode class=\"literal\"\u003ehost ... 127.0.0.1 ...\u003c/code\u003e line from \u003ccode class=\"filename\"\u003epg_hba.conf\u003c/code\u003e, or change it to a non-\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication method.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the \u003ccode class=\"filename\"\u003epg_hba.conf\u003c/code\u003e lines that specify \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e. It is seldom reasonable to use \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e for any TCP/IP connections other than those from \u003cspan class=\"systemitem\"\u003elocalhost\u003c/span\u003e (127.0.0.1).\u003c/p\u003e\n\u003c/div\u003e","manual_path":"/docs/18/auth-trust.html","related":[],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[],"signature":"","sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-trust.html","sha256":"e4c50d6f88b13feb2004634788c61e0f797ff2d5b1ab6bb86de30229cef38a87","url":"/docs/18/auth-trust.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}],"tables":[]},"ManualEvidence":{"manual_path":"/docs/18/auth-trust.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-trust.html","sha256":"e4c50d6f88b13feb2004634788c61e0f797ff2d5b1ab6bb86de30229cef38a87","url":"/docs/18/auth-trust.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"auth","Key":"trust","SourceDatabase":"center","Version":"18","Locale":"en","Title":"trust","Summary":"Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details.","BodyHTML":"\u003cdiv id=\"AUTH-TRUST\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e20.4. Trust Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eWhen \u003ccode\u003etrust\u003c/code\u003e authentication is specified, \u003cspan\u003ePostgreSQL\u003c/span\u003e assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the \u003ccode\u003edatabase\u003c/code\u003e and \u003ccode\u003euser\u003c/code\u003e columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003etrust\u003c/code\u003e authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually \u003cspan\u003e\u003cem\u003enot\u003c/em\u003e\u003c/span\u003e appropriate by itself on a multiuser machine. However, you might be able to use \u003ccode\u003etrust\u003c/code\u003e even on a multiuser machine, if you restrict access to the server\u0026#39;s Unix-domain socket file using file-system permissions. To do this, set the \u003ccode\u003eunix_socket_permissions\u003c/code\u003e (and possibly \u003ccode\u003eunix_socket_group\u003c/code\u003e) configuration parameters as described in \u003ca href=\"/docs/18/runtime-config-connection.html\" rel=\"nofollow\"\u003eSection 19.3\u003c/a\u003e. Or you could set the \u003ccode\u003eunix_socket_directories\u003c/code\u003e configuration parameter to place the socket file in a suitably restricted directory.\u003c/p\u003e\n\u003cp\u003eSetting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the \u003ccode\u003ehost ... 127.0.0.1 ...\u003c/code\u003e line from \u003ccode\u003epg_hba.conf\u003c/code\u003e, or change it to a non-\u003ccode\u003etrust\u003c/code\u003e authentication method.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003etrust\u003c/code\u003e authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the \u003ccode\u003epg_hba.conf\u003c/code\u003e lines that specify \u003ccode\u003etrust\u003c/code\u003e. It is seldom reasonable to use \u003ccode\u003etrust\u003c/code\u003e for any TCP/IP connections other than those from \u003cspan\u003elocalhost\u003c/span\u003e (127.0.0.1).\u003c/p\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"a6b10f399fac087675e294a4a4d28f8f34f266b2271c2669c31a78fe7275f1d4","Payload":{"description":["Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details."],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-TRUST\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.4. Trust Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eWhen \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is specified, \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e assumes that anyone who can connect to the server is authorized to access the database with whatever database user name they specify (even superuser names). Of course, restrictions made in the \u003ccode class=\"literal\"\u003edatabase\u003c/code\u003e and \u003ccode class=\"literal\"\u003euser\u003c/code\u003e columns still apply. This method should only be used when there is adequate operating-system-level protection on connections to the server.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is appropriate and very convenient for local connections on a single-user workstation. It is usually \u003cspan class=\"emphasis\"\u003e\u003cem\u003enot\u003c/em\u003e\u003c/span\u003e appropriate by itself on a multiuser machine. However, you might be able to use \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e even on a multiuser machine, if you restrict access to the server's Unix-domain socket file using file-system permissions. To do this, set the \u003ccode class=\"varname\"\u003eunix_socket_permissions\u003c/code\u003e (and possibly \u003ccode class=\"varname\"\u003eunix_socket_group\u003c/code\u003e) configuration parameters as described in \u003ca class=\"xref\" href=\"/docs/18/runtime-config-connection.html\" title=\"19.3. Connections and Authentication\"\u003eSection 19.3\u003c/a\u003e. Or you could set the \u003ccode class=\"varname\"\u003eunix_socket_directories\u003c/code\u003e configuration parameter to place the socket file in a suitably restricted directory.\u003c/p\u003e\n\u003cp\u003eSetting file-system permissions only helps for Unix-socket connections. Local TCP/IP connections are not restricted by file-system permissions. Therefore, if you want to use file-system permissions for local security, remove the \u003ccode class=\"literal\"\u003ehost ... 127.0.0.1 ...\u003c/code\u003e line from \u003ccode class=\"filename\"\u003epg_hba.conf\u003c/code\u003e, or change it to a non-\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication method.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication is only suitable for TCP/IP connections if you trust every user on every machine that is allowed to connect to the server by the \u003ccode class=\"filename\"\u003epg_hba.conf\u003c/code\u003e lines that specify \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e. It is seldom reasonable to use \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e for any TCP/IP connections other than those from \u003cspan class=\"systemitem\"\u003elocalhost\u003c/span\u003e (127.0.0.1).\u003c/p\u003e\n\u003c/div\u003e","related":[],"sections":[],"tables":[]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
