Documenting safe practices for qualified function calls

Поиск
Список
Период
Сортировка
От Noah Misch
Тема Documenting safe practices for qualified function calls
Дата
Msg-id 20180721012446.GA1840594@rfd.leadboat.com
обсуждение исходный текст
Список pgsql-docs
The CVE-2018-1058 documentation change, commit 5770172, directed readers to
secure their schema usage patterns.  That made secure their use of unqualified
function and operator names.  Sometimes one wishes to call an object outside
search_path via a qualified name.  That has its own security considerations,
which we hadn't documented to the same degree.  The security team discussed
this and concluded that the lack of documentation did not itself constitute a
security flaw.  I did prepare the attached patch, which Jonathan Katz
reviewed.  I'm posting it here in case anyone else wishes to review it.

Thanks,
nm

Вложения

В списке pgsql-docs по дате отправления:

Предыдущее
От: Pavel Golub
Дата:
Сообщение: Re: Images in the official documentation
Следующее
От: Jürgen Purtz
Дата:
Сообщение: Re: Images in the official documentation