Re: Catalog Security WAS: Views, views, views: Summary

Поиск
Список
Период
Сортировка
От Andrew Dunstan
Тема Re: Catalog Security WAS: Views, views, views: Summary
Дата
Msg-id 4284F34D.9070108@dunslane.net
обсуждение исходный текст
Ответ на Re: Catalog Security WAS: Views, views, views: Summary of Arguments  (Andrew - Supernews <andrew+nonews@supernews.com>)
Ответы Re: Catalog Security WAS: Views, views, views: Summary  (Russell Smith <mr-russ@pws.com.au>)
Список pgsql-hackers

Andrew - Supernews wrote:

>>
>>1) The "ISP" case, where you want to hide all catalog information from the 
>>users except the database owner or superuser.
>>    
>>
>
>I don't believe this is ever feasible in practice, since client interfaces
>at any level higher than libpq will need to access metadata corresponding
>to the data they are retrieving.
>
>  
>

In the general case you might well be right. Following a scheme like I 
have in mind is not something that would be transparent to the 
application - it will probably impose some serious limits on the app. 
The little sample application I did for testing did everything by stored 
procedure. Anyway, as I said, it's a project for the future.

cheers

andrew



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Josh Berkus
Дата:
Сообщение: Re: Fix PID file location?
Следующее
От: "Jim C. Nasby"
Дата:
Сообщение: Re: Views, views, views: Summary of Arguments