Re: [GENERAL] worried about PGPASSWORD drop

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: [GENERAL] worried about PGPASSWORD drop
Дата
Msg-id 20020828220555.328b9352.alvherre@atentus.com
обсуждение исходный текст
Ответы Re: [GENERAL] worried about PGPASSWORD drop  (Bruce Momjian <pgman@candle.pha.pa.us>)
Re: [GENERAL] worried about PGPASSWORD drop  ("Nigel J. Andrews" <nandrews@investsystems.co.uk>)
Re: [GENERAL] worried about PGPASSWORD drop  (Bruce Momjian <pgman@candle.pha.pa.us>)
Список pgsql-patches
En Wed, 28 Aug 2002 17:33:34 -0400 (EDT)
Bruce Momjian <pgman@candle.pha.pa.us> escribió:

> Alvaro Herrera wrote:
> > Bruce Momjian dijo:
> >
> > > Tom Lane wrote:
> >
> > > > If you want to put in security restrictions that are actually useful,
> > > > where is the code to verify that PGPASSWORDFILE points at a
> > > > non-world-readable file?  That needs to be there now, not later, or
> > > > we'll have people moaning about backward compatibility when we finally
> > > > do plug that hole.
> > >
> > > Agreed.
> >
> > Point taken, will look into it later.
>
> Here is some code from postmaster.c that may help:

Thank you.  Patch attached.  Note that it also checks group access; I think
that is desired as well.

--
Alvaro Herrera (<alvherre[a]atentus.com>)
"Cuando mañana llegue pelearemos segun lo que mañana exija" (Mowgli)

Вложения

В списке pgsql-patches по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Anonymous-record-types omission
Следующее
От: Tom Lane
Дата:
Сообщение: Re: small mistakes in func.sgml