Best practice? Web application: single PostgreSQL user vs. multiple users

Поиск
Список
Период
Сортировка
От Keith G. Murphy
Тема Best practice? Web application: single PostgreSQL user vs. multiple users
Дата
Msg-id 40041924.2030200@mindspring.com
обсуждение исходный текст
Ответы Re: Best practice? Web application: single PostgreSQL  ("John Sidney-Woollett" <johnsw@wardbrook.com>)
Re: Best practice? Web application: single PostgreSQL  ("scott.marlowe" <scott.marlowe@ihs.com>)
Re: Best practice? Web application: single PostgreSQL  (netadmin@vcsn.com)
Список pgsql-general
I'm trying to get a feel for what most people are doing or consider best
practice.

Given a mod_perl application talking to a PostgreSQL database on the
same host, where different users are logging onto the web server using
LDAP for authentication, do most people

1) have the web server connecting to the database using its own user
account (possibly through ident), and controlling access to different
database entities strictly through the application itself

2) have the web server connecting to the database actually using the
user's account (possibly using LDAP authentication against PostgreSQL),
and controlling access to different database entities through GRANT, etc.

Obviously, (2) leads to more database connections, and you still have to
have the application do some work in terms of which forms are available
to which users, etc.  But I'm a little worried about whether it's best
security practice.



В списке pgsql-general по дате отправления:

Предыдущее
От: "Keith C. Perry"
Дата:
Сообщение: Re: cryptography, was Drawbacks of using BYTEA for PK?
Следующее
От: "John Sidney-Woollett"
Дата:
Сообщение: Re: Best practice? Web application: single PostgreSQL