hostname:port:database:username:password
-Each of these fields may be a literal name or *, which
-matches anything. The first matching entry will be used, so put more-specific
-entries first. When an entry contain : or
-\, it must be escaped with \.
+Each of the first four fields may be a literal value, or *,
+which
+matches anything. The password field from the first line that matches the
+current connection parameters will be used. (Therefore, put more-specific
+entries first when you are using wildcards.)
+If an entry needs to contain : or
+\, escape this character with \.
The permissions on .pgpass must disallow any