Re: RFC: Security documentation

Поиск
Список
Период
Сортировка
От Jim C. Nasby
Тема Re: RFC: Security documentation
Дата
Msg-id 20040211174624.GC32360@nasby.net
обсуждение исходный текст
Ответ на Re: RFC: Security documentation  (Josh Berkus <josh@agliodbs.com>)
Ответы Re: RFC: Security documentation  (Robert Treat <xzilla@users.sourceforge.net>)
Список pgsql-hackers
On Sun, Feb 08, 2004 at 11:24:56PM -0800, Josh Berkus wrote:
> The problem with this approach, of course, is that large application 
> developers generally like to make the database fairly "passive" and put all 
> business & security logic in the middleware.   I do think it would be useful 
> for them to realize that they are sacrificing a significant portion of their 
> data security by doing so.
Perhaps what would be best is some kind of a 'best practices' guide.
There's far more that people should consider beyond just quoting
strings; Josh's example is just one thing.

If written carefully, such a guide could serve both experienced DBAs as
well as people who are very new to databases, since every database has
it's own prefered way of doing things.
-- 
Jim C. Nasby, Database Consultant                  jim@nasby.net
Member: Triangle Fraternity, Sports Car Club of America
Give your computer some brain candy! www.distributed.net Team #1828

Windows: "Where do you want to go today?"
Linux: "Where do you want to go tomorrow?"
FreeBSD: "Are you guys coming, or what?"


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Mark Gibson
Дата:
Сообщение: Re: [GENERAL] dblink - custom datatypes don't work
Следующее
От: Alvaro Herrera
Дата:
Сообщение: Re: PITR Dead horse?