Re: Permissions on aggregate component functions

Поиск
Список
Период
Сортировка
От Bruno Wolff III
Тема Re: Permissions on aggregate component functions
Дата
Msg-id 20050127214206.GA8250@wolff.to
обсуждение исходный текст
Ответ на Permissions on aggregate component functions  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
On Thu, Jan 27, 2005 at 15:27:54 -0500, Tom Lane <tgl@sss.pgh.pa.us> wrote:
> I just noticed that there is no permission check anywhere in CREATE
> AGGREGATE concerning the aggregate's transition and final functions.
> This means anyone can trivially bypass the function EXECUTE permission
> check: just make an aggregate function to call it for you.  (Now, this
> works only for functions whose signature fits what an aggregate
> expects, but for most one- and two-argument functions you can do it.)
> 
> Clearly this is a must-fix issue, but I'm wondering exactly where the
> check should be enforced.  Is it sufficient to check at the time of
> CREATE AGGREGATE that the creator has appropriate rights, or do we need
> to do it every time the aggregate is used?

I would think both would be best. If you don't check at runtime the function
owner can't easily revoke access (dropping the function might be a pain
if it is used in lots of places). It is nice to check at creation so as
to give immediate feedback if there is a problem.


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Oleg Bartunov
Дата:
Сообщение: Re: strange 'vacuum verbose analyze' behaviour
Следующее
От: ITAGAKI Takahiro
Дата:
Сообщение: Re: [PATCHES] WAL: O_DIRECT and multipage-writer