Files
odoo_source/odoo/service
kedwards 4015f90bde [IMP] core: improve behaviour of Odoo on Postgres 15+
Postgres 15.0 has started enforcing a [long-standing
recommendation][secure-schema] of the `public` schema not being
`CREATE`-granted to every user, as in users which are neither
administrators nor owners of the database can not create DDL objects
(tables, views, ...) in the schema.

As Odoo [recommends using a non-admin non-owner user][configuring]
this would be the normal deployment mode of a production Odoo system,
following which Odoo would be unable to initialize the database and
install new modules.

Although the official recommendation is to create a schema with the
same name as and owned by the low-access user, the threat model does
not really affect Odoo as it always connects to the database with the
same user (or close enough). Odoo's behaviour is much closer to usage
pattern 5.9.6 ¶ 3:

> the database has a single user or a few mutually-trusting users

It also would not really work, as one could create and possibly
initialize the database with one user (e.g. using the command line),
then per [guide][configuration] run Odoo using a different user, which
would not be able to see the schema created for the first user and
thus would have to perform their own setup in an unrelated
schema (which it would have to create first). Resulting in an unused
full installation (with the modules and configuration the original
creator wanted) and a separate empty installation at best.

Thus implement the setup for 5.9.6 ¶ 3:

> grant privileges to create in the public schema

[configuring]: https://www.odoo.com/documentation/16.0/administration/install/deploy.html#configuring-odoo
[secure-schema]: https://www.postgresql.org/docs/15/ddl-schemas.html#DDL-SCHEMAS-PATTERNS

closes odoo/odoo#116172

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2023-10-06 13:08:52 +00:00
..
…
…
…