Hi, and thanks (both of you!)Shouldn't thecreate role my_user NOINHERIT;avoid this? And since not, why? :-)
We might need to improve documentation surrounding the public pseudo-role a bit. Since it’s not a true group role I suspect inherit/noinherit doesn’t apply. (You also cannot SET to it, nor admin it - not tested.) Losing the execute privilege on every built-in function would be way too annoying.
David J.