Re: bug in json_to_record with arrays

Поиск
Список
Период
Сортировка
От Stephen Frost
Тема Re: bug in json_to_record with arrays
Дата
Msg-id 20141126214553.GK28859@tamriel.snowman.net
обсуждение исходный текст
Ответ на Re: bug in json_to_record with arrays  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: bug in json_to_record with arrays  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
* Tom Lane (tgl@sss.pgh.pa.us) wrote:
> As far as your request for a better error message is concerned, I'm a
> bit inclined to lay the blame on array_in rather than the JSON code.
> Wouldn't it be better if it said
>
>      ERROR:  invalid input syntax for array: "["potter","chef","programmer"]"
>      DETAIL: Dimension value is missing.

Sounds pretty reasonable to me, but I would just caution that we should
check if that's considered 'leakproof' or not (or, if it is, if it'd
ever possibly leak data it shouldn't or if it would only ever return
information provided by the user).

Otherwise, someone might be able to convince the planner to push it down
below a security qual and expose data from rows which shouldn't be
visible.
Thanks!
    Stephen

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Andrew Dunstan
Дата:
Сообщение: Re: bug in json_to_record with arrays
Следующее
От: Andrew Dunstan
Дата:
Сообщение: memory explosion on planning complex query