Re: dblink connection security
| От | Gregory Stark |
|---|---|
| Тема | Re: dblink connection security |
| Дата | |
| Msg-id | 87k5tab404.fsf@oxford.xeocode.com обсуждение исходный текст |
| Ответ на | Re: dblink connection security (Joe Conway <mail@joeconway.com>) |
| Ответы |
Re: dblink connection security
|
| Список | pgsql-patches |
"Joe Conway" <mail@joeconway.com> writes: > See my last email... > > Consider a scenario like "package <x> uses <arbitrary function y in an > untrusted language z>". Exact same concerns arise. Well arbitrary function may or may not actually do anything that needs to be restricted. If it does then yes the same concerns arise and the same conclusion reached. That users should be granted permission to execute it based on local policies. Certainly granting execute permission to public by default is a bad start in that regard. -- Gregory Stark EnterpriseDB http://www.enterprisedb.com
В списке pgsql-patches по дате отправления: