Re: pl/pgsql enabled by default

Поиск
Список
Период
Сортировка
От Mike Mascari
Тема Re: pl/pgsql enabled by default
Дата
Msg-id 427D728B.8020105@mascari.com
обсуждение исходный текст
Ответ на Re: pl/pgsql enabled by default  (Neil Conway <neilc@samurai.com>)
Ответы Re: pl/pgsql enabled by default  (Neil Conway <neilc@samurai.com>)
Список pgsql-hackers
Neil Conway wrote:
> Andrew Sullivan wrote:
>> This is not really analogous, because those are already on
> Security (in the limited sense of "disabling features by default") is 
> not free; there is a tradeoff between security and convenience, security 
> and administrative simplicity, and so on. Given that I have yet to see a 
> single substantive argument for pl/pgsql being a security risk that has 
> withstood any scrutiny, I don't see that the "security" side of the 
> tradeoff has a lot of merit.

People who use views to achieve row security, which is a rather common 
paradigm, cannot allow users to create functions with side effects.

Mike Mascari


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tatsuo Ishii
Дата:
Сообщение: Re: Patch for collation using ICU
Следующее
От: Tatsuo Ishii
Дата:
Сообщение: Re: [GENERAL] Invalid unicode in COPY problem