Re: Allowing to create LEAKPROOF functions to non-superuser

Поиск
Список
Период
Сортировка
Andrey Borodin <x4mmm@yandex-team.ru> writes:
> Currently only superuser is allowed to create LEAKPROOF functions because leakproof functions can see tuples which
havenot yet been filtered out by security barrier views or row level security policies. 

Yeah.

> But managed cloud services typically do not provide superuser roles.

This is not a good argument for relaxing superuser requirements.

            regards, tom lane



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Andrey Borodin
Дата:
Сообщение: Allowing to create LEAKPROOF functions to non-superuser
Следующее
От: Andres Freund
Дата:
Сообщение: Re: PANIC: wrong buffer passed to visibilitymap_clear