Re: AW: [Extern] Re: PG16.1 security breach?

Поиск
Список
Период
Сортировка
От Laurenz Albe
Тема Re: AW: [Extern] Re: PG16.1 security breach?
Дата
Msg-id 6d223a4891287cfb08b720103faef2da1b5719f3.camel@cybertec.at
обсуждение исходный текст
Ответ на AW: [Extern] Re: PG16.1 security breach?  ("Zwettler Markus (OIZ)" <Markus.Zwettler@zuerich.ch>)
Ответы PG16.1 security breach?
Список pgsql-general
On Fri, 2024-06-07 at 13:54 +0000, Zwettler Markus (OIZ) wrote:
> > Another point to keep in mind is that by default, execute privilege is granted to
> > PUBLIC for newly created functions (see Section 5.7 for more information).
>
> Argh. No! What a bad habit!
>
> Might be good idea for an enhancement request to create a global parameter to disable this habit.

I don't see the problem, since the default execution mode for functions is
SECURITY INVOKER.

But you can easily change that:

  ALTER DEFAULT PRIVILEGES FOR ROLE function_creator REVOKE EXECUTE ON FUNCTION FROM PUBLIC;

Yours,
Laurenz Albe



В списке pgsql-general по дате отправления:

Предыдущее
От: "David G. Johnston"
Дата:
Сообщение: Re: PG16.1 security breach?
Следующее
От: Adrian Klaver
Дата:
Сообщение: Re: AW: [Extern] Re: PG16.1 security breach?