Re: Fixing insecure security definer functions

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Fixing insecure security definer functions
Дата
Msg-id 26354.1175192378@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Fixing insecure security definer functions  (Stephen Frost <sfrost@snowman.net>)
Список pgsql-hackers
Stephen Frost <sfrost@snowman.net> writes:
> * Merlin Moncure (mmoncure@gmail.com) wrote:
>> maybe security definer functions should raise a warning for implicit
>> PATH NONE, and possibly even deprecate that behavior and force people
>> to type it out in future (8.4+) releases.

> While I agree that raising a warning makes sense I don't believe it
> should be forced.

A WARNING seems reasonable to me too.  I'd just do it on the combination
of SECURITY DEFINER with PATH NONE, regardless of how you typed it
exactly.  ALTERing a function into that configuration should draw the
same warning.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Merlin Moncure"
Дата:
Сообщение: Re: Fixing insecure security definer functions
Следующее
От: "Sailesh Krishnamurthy"
Дата:
Сообщение: Re: Concurrent connections in psql