reuse sysids security hole?
| От | Andrew Dunstan |
|---|---|
| Тема | reuse sysids security hole? |
| Дата | |
| Msg-id | 3F38FB9F.5000304@dunslane.net обсуждение исходный текст |
| Ответы |
Re: reuse sysids security hole?
|
| Список | pgsql-hackers |
(Thought triggered by something Tom said the other day) Is this a security hole? Looks like one to me. Would it be better to use a sequence generator for sysids instead of using max+1 on the user table? Or else store the last sysid used somewhere? andrew facetest=# create user blurfl; CREATE USER facetest=# create table blurfltable (a text, b text); CREATE TABLE facetest=# alter table blurfltable owner to blurfl; ALTER TABLE facetest=# drop user blurfl; DROP USER facetest=# create user floobl; CREATE USER facetest=# \dt blurfltable List of relationsSchema | Name | Type | Owner --------+-------------+-------+--------public | blurfltable | table | floobl (1 row) facetest=#
В списке pgsql-hackers по дате отправления: