reuse sysids security hole?

Поиск
Список
Период
Сортировка
От Andrew Dunstan
Тема reuse sysids security hole?
Дата
Msg-id 3F38FB9F.5000304@dunslane.net
обсуждение исходный текст
Ответы Re: reuse sysids security hole?  (Gavin Sherry <swm@linuxworld.com.au>)
Список pgsql-hackers
(Thought triggered by something Tom said the other day)

Is this a security hole? Looks like one to me. Would it be better to use 
a sequence generator for sysids instead of using max+1 on the user 
table? Or else store the last sysid used somewhere?

andrew

facetest=# create user blurfl;
CREATE USER
facetest=# create table blurfltable (a text, b text);
CREATE TABLE
facetest=# alter table blurfltable owner to blurfl;
ALTER TABLE
facetest=# drop user blurfl;
DROP USER
facetest=# create user floobl;
CREATE USER
facetest=# \dt blurfltable          List of relationsSchema |    Name     | Type  | Owner 
--------+-------------+-------+--------public | blurfltable | table | floobl
(1 row)

facetest=#



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Jan Wieck
Дата:
Сообщение: Re: Farewell
Следующее
От: Gavin Sherry
Дата:
Сообщение: Re: reuse sysids security hole?