Re: pgsql: Allow 'sslkey' and 'sslcert' in postgres_fdw user mappings

Поиск
Список
Период
Сортировка
От Andrew Dunstan
Тема Re: pgsql: Allow 'sslkey' and 'sslcert' in postgres_fdw user mappings
Дата
Msg-id 2fb2a879-725b-57c1-bd15-a9111a03416c@2ndQuadrant.com
обсуждение исходный текст
Ответ на Re: pgsql: Allow 'sslkey' and 'sslcert' in postgres_fdw user mappings  (Craig Ringer <craig@2ndquadrant.com>)
Список pgsql-hackers
On 1/20/20 2:48 AM, Craig Ringer wrote:
> On Thu, 9 Jan 2020 at 22:38, Christoph Berg <myon@debian.org
> <mailto:myon@debian.org>> wrote:
>
>     Re: Robert Haas 2020-01-09
>     <CA+TgmoZEjyv_PD=2cinkbDA_chyLNAcBPL_9bKJQ6bc=nw+FHA@mail.gmail.com
>     <mailto:nw%2BFHA@mail.gmail.com>>
>     > Does this mean that a non-superuser can induce postgres_fdw to
>     read an
>     > arbitrary file from the local filesystem?
>
>     Yes, see my comments in the "Allow 'sslkey' and 'sslcert' in
>     postgres_fdw user mappings" thread.
>
>
> Ugh, I misread your comment.
>
> You raise a sensible concern.
>
> These options should be treated the same as the proposed option to
> allow passwordless connections: disallow creation or alteration of FDW
> connection strings that use them by non-superusers. So a superuser can
> define a user mapping that uses these options, but normal users may not.
>
>


Already done.


cheers


andrew


-- 
Andrew Dunstan                https://www.2ndQuadrant.com
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Add support for automatically updating Unicode derived files
Следующее
От: Peter Eisentraut
Дата:
Сообщение: Re: Unicode normalization SQL functions