Re: Views, views, views: Summary of Arguments

Поиск
Список
Период
Сортировка
От Andrew Dunstan
Тема Re: Views, views, views: Summary of Arguments
Дата
Msg-id 4284DCB1.5060407@dunslane.net
обсуждение исходный текст
Ответ на Re: Views, views, views: Summary of Arguments  (Josh Berkus <josh@agliodbs.com>)
Ответы Re: Views, views, views: Summary of Arguments  (Josh Berkus <josh@agliodbs.com>)
Список pgsql-hackers

Josh Berkus wrote:

>Andrew, Merlin,
>
>  
>
>>My approach was to remove all significant permissions (including on the
>>catalog) from public and regrant them to a pseudopublic group,
>>comprising designated users. The designated users would notice no
>>difference at all, while everyone else would be able to see only what
>>was explicitly granted to them. But there would be lots of testing and
>>thinking to be done before releasing it into the wild :-)
>>    
>>
>
><plug>Doesn't it seem like a really complete set of system views (based on 
>information_schema or otherwise) would potentially allow securing the 
>pg_catalog?</plug>
>
>  
>

Not really, no. It would just be one more thing that my hardening script 
had to remove permissions from.

I still have an open mind about the sysviews project, but the more 
oversold, hyped and promoted with bogus arguments it gets the more 
skeptical I become.

cheers

andrew


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Views, views, views: Summary of Arguments
Следующее
От: Josh Berkus
Дата:
Сообщение: Re: Views, views, views: Summary of Arguments