{"Entry":{"collection":"guc","key":"createrole_self_grant","name":"createrole_self_grant","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Client Connection Defaults / Statement Behavior","category_zh":"","changed_in":["18"],"changes":[{"documentation_changed":false,"fields":{},"from":"15","status":"added","to":"16"},{"documentation_changed":false,"fields":{"extra_desc":{"from":null,"to":"An empty string disables automatic self grants."}},"from":"17","status":"changed","to":"18"}],"content_hash":"2267646214ad197332a6dd3cab185761b9fde46ea5a50e3248251ade0753b18c","context":"","default_changed_in":[],"default_history":[{"from":"16","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Use a dedicated analytical role if createrole_self_grant must differ, and verify that exports, triggers, policies, and name resolution still preserve data correctness.","oltp":"Treat createrole_self_grant as a correctness or security control, not a throughput knob. Grant SET authority narrowly and establish it from trusted role or application policy.","small":"Keep createrole_self_grant at its safe default unless a documented repair or compatibility workflow requires otherwise; record and automatically restore temporary changes."},"mechanism":["createrole_self_grant sets whether a CREATEROLE user automatically grants the role to themselves, and with which options. An empty string disables automatic self grants. The accepted options are set, inherit, or both; it automates a grant the creating CREATEROLE user could issue with ADMIN OPTION and does not affect superusers.","createrole_self_grant is a USER-context setting. An authorized role can change it for a session, while ALTER ROLE or ALTER DATABASE can establish a default for future sessions.","Because session state can survive in pooled connections, role defaults, SET privilege, RESET behavior, and application checkout hooks are part of the control's effective boundary."],"pitfalls":["Changing createrole_self_grant in one session and assuming role defaults, database defaults, or other pooled sessions changed with it.","Granting broad SET rights to a control that can change correctness, policy enforcement, or name resolution.","Failing to reset a security-sensitive session value before a pooled connection is reused by another request.","Changing createrole_self_grant globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: createrole_self_grant","url":"https://www.postgresql.org/docs/19/runtime-config-client.html#GUC-CREATEROLE-SELF-GRANT"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["search_path","row_security","session_replication_role","event_triggers","restrict_nonsystem_relation_kind"],"summary":"createrole_self_grant is the PostgreSQL setting that defines whether a CREATEROLE user automatically grants the role to themselves, and with which options."},"enumvals":[],"first_version":"16","group":"Client Connection Defaults","group_slug":"client","imported_at":"2026-09-27T17:57:30.997196+08:00","intro_commit":{"authored_at":"2023-01-10T12:44:49-05:00","discussion":["https://postgr.es/m/CA+TgmobN59ct+Emmz6ig1Nua2Q-_o=r6DSD98KfU53kctq_kQw@mail.gmail.com"],"hash":"e5b8a4c098ad6add39626a14475148872cd687e0","subject":"Add new GUC createrole_self_grant.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=e5b8a4c098ad6add39626a14475148872cd687e0"},"key":"createrole_self_grant","last_version":"20","max_val":"","min_val":"","name":"createrole_self_grant","position":73,"present_in":["16","17","18","19","20"],"short_desc":"If a user who has CREATEROLE but not SUPERUSER creates a role, and if this is set to a non-empty value, the newly-created role will be granted to the creating user with the options specified.","short_desc_zh":"","source_rev":"english-manuals:4fe880d8d185142dd83970fc23b0ddef1e98ddd361ec41c93b2e7a76b4f87d94","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"createrole_self_grant","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"createrole_self_grant","SourceRevision":"english-manuals:4fe880d8d185142dd83970fc23b0ddef1e98ddd361ec41c93b2e7a76b4f87d94","Facts":{"boot_val":"","category":"Client Connection Defaults / Statement Behavior","context":"user","description":"If a user who has CREATEROLE but not SUPERUSER creates a role, and if this is set to a non-empty value, the newly-created role will be granted to the creating user with the options specified. The value must be set, inherit, or a comma-separated list of these. The default value is an empty string, which disables the feature. The purpose of this option is to allow a CREATEROLE user who is not a superuser to automatically inherit, or automatically gain the ability to SET ROLE to, any created users. Since a CREATEROLE user is always implicitly granted ADMIN OPTION on created roles, that user could always execute a GRANT statement that would achieve the same effect as this setting. However, it can be convenient for usability reasons if the grant happens automatically. A superuser automatically inherits the privileges of every role and can always SET ROLE to any role, and this setting can be used to produce a similar behavior for CREATEROLE users for users which they create.","doc":{"anchor":"GUC-CREATEROLE-SELF-GRANT","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"An empty string disables automatic self grants.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"createrole_self_grant","short_desc":"Sets whether a CREATEROLE user automatically grants the role to themselves, and with which options.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-CREATEROLE-SELF-GRANT","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"createrole_self_grant","SourceDatabase":"center","Version":"18","Locale":"en","Title":"createrole_self_grant","Summary":"If a user who has CREATEROLE but not SUPERUSER creates a role, and if this is set to a non-empty value, the newly-created role will be granted to the creating user with the options specified. The value must be set, inherit, or a comma-separated list of these. The default value is an empty string, which disables the feature. The purpose of this option is to allow a CREATEROLE user who is not a superuser to automatically inherit, or automatically gain the ability to SET ROLE to, any created users. Since a CREATEROLE user is always implicitly granted ADMIN OPTION on created roles, that user could always execute a GRANT statement that would achieve the same effect as this setting. However, it can be convenient for usability reasons if the grant happens automatically. A superuser automatically inherits the privileges of every role and can always SET ROLE to any role, and this setting can be used to produce a similar behavior for CREATEROLE users for users which they create.","BodyHTML":"\u003cp\u003eIf a user who has CREATEROLE but not SUPERUSER creates a role, and if this is set to a non-empty value, the newly-created role will be granted to the creating user with the options specified. The value must be set, inherit, or a comma-separated list of these. The default value is an empty string, which disables the feature. The purpose of this option is to allow a CREATEROLE user who is not a superuser to automatically inherit, or automatically gain the ability to SET ROLE to, any created users. Since a CREATEROLE user is always implicitly granted ADMIN OPTION on created roles, that user could always execute a GRANT statement that would achieve the same effect as this setting. However, it can be convenient for usability reasons if the grant happens automatically. A superuser automatically inherits the privileges of every role and can always SET ROLE to any role, and this setting can be used to produce a similar behavior for CREATEROLE users for users which they create.\u003c/p\u003e","SourceRevision":"english-manuals:4fe880d8d185142dd83970fc23b0ddef1e98ddd361ec41c93b2e7a76b4f87d94","ContentHash":"a26f5395e91bf5980c41a9ea742ef287418bbb38c300096048ac3c5a357a02a2","Payload":{"description":"If a user who has CREATEROLE but not SUPERUSER creates a role, and if this is set to a non-empty value, the newly-created role will be granted to the creating user with the options specified. The value must be set, inherit, or a comma-separated list of these. The default value is an empty string, which disables the feature. The purpose of this option is to allow a CREATEROLE user who is not a superuser to automatically inherit, or automatically gain the ability to SET ROLE to, any created users. Since a CREATEROLE user is always implicitly granted ADMIN OPTION on created roles, that user could always execute a GRANT statement that would achieve the same effect as this setting. However, it can be convenient for usability reasons if the grant happens automatically. A superuser automatically inherits the privileges of every role and can always SET ROLE to any role, and this setting can be used to produce a similar behavior for CREATEROLE users for users which they create."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
