Re: sudo-like behavior

Поиск
Список
Период
Сортировка
От Florian G. Pflug
Тема Re: sudo-like behavior
Дата
Msg-id 444A745E.2040403@phlo.org
обсуждение исходный текст
Ответ на Re: sudo-like behavior  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-general
Tom Lane wrote:
> "Florian G. Pflug" <fgp@phlo.org> writes:
>
>>Why don't you just use "SET SESSION AUTHORIZATION somerole", and then scan
>>the to-be-executel sql scripts for any occurence of "reset session authorization",
>>and ignore the script it matches.
>
> What would probably be better is a way to do SET SESSION AUTHORIZATION
> and then abandon the underlying superuser privilege, thereby absolutely
> guaranteeing that the session can't do anything the selected userid
> shouldn't be able to do.  You'd have to start a new session for each
> cronjob, but that would be a Really Good Idea anyway, given the lack of
> any way to fully restore a session to default state.

My "solution" (or hack ;-) ) was meant to work with current versions of postgres..
Of course, a command like "set session authorization <user> final" or such would be
a better way - maybe something for 8.2? ;-))

mfg, Florian Pflug


В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: sudo-like behavior
Следующее
От: "Florian G. Pflug"
Дата:
Сообщение: Automatically assuming a specific role after connecting to pg