Re: Redact user password on pg_stat_statements
От | Tom Lane |
---|---|
Тема | Re: Redact user password on pg_stat_statements |
Дата | |
Msg-id | 3134386.1740154091@sss.pgh.pa.us обсуждение исходный текст |
Ответ на | Redact user password on pg_stat_statements (Matheus Alcantara <matheusssilv97@gmail.com>) |
Ответы |
Re: Redact user password on pg_stat_statements
Re: Redact user password on pg_stat_statements |
Список | pgsql-hackers |
Matheus Alcantara <matheusssilv97@gmail.com> writes: > Attached a patch to redact the password value from pg_stat_statements_view when > executing: > { CREATE|ALTER} {USER|ROLE|GROUP } identifier { [WITH] [ENCRYPTED] > PASSWORD 'value' } Please see previous threads about hiding this sort of information, most recently [1]. It's a slippery slope for which there are no real fixes, and even partial fixes like this one are horrid kluges. One obvious objection to the direction you propose here is that it does nothing for pg_stat_activity, nor for the server log if log_statement is enabled. The right answer is to never send cleartext passwords to the server in the first place. regards, tom lane [1] https://www.postgresql.org/message-id/flat/18817-771682052a364bfe%40postgresql.org
В списке pgsql-hackers по дате отправления: