Re: Proposed patch to disallow password=foo in database name parameter

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: Proposed patch to disallow password=foo in database name parameter
Дата
Msg-id 20071211122246.GE4708@alvh.no-ip.org
обсуждение исходный текст
Ответ на Re: Proposed patch to disallow password=foo in database name parameter  (Magnus Hagander <magnus@hagander.net>)
Ответы Re: Proposed patch to disallow password=foo in databasename parameter  (Heikki Linnakangas <heikki@enterprisedb.com>)
Список pgsql-patches
Magnus Hagander wrote:
> On Mon, Dec 10, 2007 at 10:47:19PM -0500, Tom Lane wrote:

> If we want to prevent it for psql, we should actually prevent it *in* psql,
> not in libpq. There are an infinite number of scenarios where it's
> perfectly safe to put the password there... If we want to do it share, we
> should add a function like PQSanitizeConnectionString() that will remove
> it, that can be called from those client apps that may be exposing it.
>
> There are also platforms that don't show the full commandline to other
> users - or even other processes - that aren't affected, of course.

One idea is to have psql "hide" the password on the ps status.  That way
it becomes less of a security issue.  It would still be a problem on
certain operating systems, but at least several common platforms would
be covered.

--
Alvaro Herrera                         http://www.flickr.com/photos/alvherre/
Officer Krupke, what are we to do?
Gee, officer Krupke, Krup you! (West Side Story, "Gee, Officer Krupke")

В списке pgsql-patches по дате отправления:

Предыдущее
От: Dave Page
Дата:
Сообщение: Re: pgbench - startup delay
Следующее
От: Heikki Linnakangas
Дата:
Сообщение: Re: Proposed patch to disallow password=foo in databasename parameter