Re: Increasing security in a shared environment ...

Поиск
Список
Период
Сортировка
От Christopher Kings-Lynne
Тема Re: Increasing security in a shared environment ...
Дата
Msg-id 4067AA42.8070002@familyhealth.com.au
обсуждение исходный текст
Ответ на Increasing security in a shared environment ...  ("Marc G. Fournier" <scrappy@postgresql.org>)
Ответы Re: Increasing security in a shared environment ...  (Andrew Dunstan <andrew@dunslane.net>)
Re: Increasing security in a shared environment ...  (Euler Taveira de Oliveira <euler@ufgnet.ufg.br>)
Список pgsql-hackers
> "The \l command should only list databases that the current user is
> authorized for, the \du command should only list users authorized for the
> current database (and perhaps only superusers should get even that much
> information), etc.  Perhaps it is possible to set PG to do this, but that
> should probably be the default."
> 
> This is from a PgSQL vs MySQL thread on -general ... how hard would it be
> make it so that a non-superuse user can't do a \l and see everyone's
> databases?  Or, when doing a \d in a database you are able to connect to,
> it would only show those tables that you are authorized for?

Well, you can just go SELECT * FROM pg_database;  so fixing \l won't do 
anything.

I too would like to see more security in this respect, but it will be 
difficult if not impossible to implement methinks...

Chris



В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Marc G. Fournier"
Дата:
Сообщение: Increasing security in a shared environment ...
Следующее
От: Joe Conway
Дата:
Сообщение: Re: Fuzzy cost comparison to eliminate redundant planning