Re: pl/pgsql enabled by default

Поиск
Список
Период
Сортировка
От Josh Berkus
Тема Re: pl/pgsql enabled by default
Дата
Msg-id 200505081103.36708.josh@agliodbs.com
обсуждение исходный текст
Ответ на Re: pl/pgsql enabled by default  (Mike Mascari <mascarm@mascari.com>)
Ответы Re: pl/pgsql enabled by default  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-hackers
Mike,

> I think most people coming from any other enterprise-class RDBMS
> environment will be surprised that they cannot use VIEWs to provide
> user-specific views on data. I could be wrong, but I'd put money on it...

Well, I'd say that giving regular users the "create" permission on your 
database/schema is unwise, period.   I don't, even when the only user is 
"phpuser".  SQL injections attacks are no fun.

Also, as Andrew points out, this can't be used to circumvent view-based 
security if you've set it up correctly; if the user can't "select * from 
table", then he can't write a function to "select * from table."  

-- 
Josh Berkus
Aglio Database Solutions
San Francisco


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Andrew - Supernews
Дата:
Сообщение: Re: Views, views, views! (long)
Следующее
От: Josh Berkus
Дата:
Сообщение: Re: Can we get patents?