Re: Re: [PATCHES] Fw: Isn't pg_statistic a security hole - Solution Proposal
| От | Joe Conway |
|---|---|
| Тема | Re: Re: [PATCHES] Fw: Isn't pg_statistic a security hole - Solution Proposal |
| Дата | |
| Msg-id | 006301c0f470$1d8dca40$d7d310ac@jecw2k1 обсуждение исходный текст |
| Ответ на | Re: Re: [PATCHES] Fw: Isn't pg_statistic a security hole - Solution Proposal (Peter Eisentraut <peter_e@gmx.net>) |
| Ответы |
Re: Re: [PATCHES] Fw: Isn't pg_statistic a security hole - Solution Proposal
|
| Список | pgsql-hackers |
> What I suggest we do is apply the portions of Joe's latest patch that > support has_table_privilege with OID inputs and with NAME inputs, > omitting the combinations that take TEXT inputs and do casefolding. > We can add that part later if it proves that people do indeed want it. > > I have specific reasons for wanting to keep the functions accepting > NAME rather than TEXT: that will save a run-time type conversion in the > common case where one is reading the input from a system catalog, and > it will at least provide automatic truncation of overlength names when > one is accepting a literal. (I trust Peter won't object to that ;-).) > I'll rework the patch per the above and resend. Thanks, -- Joe
В списке pgsql-hackers по дате отправления: