Re: RESET ROLE and search_path, Connection pool
| От | Derrick Rice | 
|---|---|
| Тема | Re: RESET ROLE and search_path, Connection pool | 
| Дата | |
| Msg-id | AANLkTikbHNZWU_4WvRE3VTEJZQk8L8RAqUhz8F=7Y7n0@mail.gmail.com обсуждение исходный текст | 
| Ответ на | RESET ROLE and search_path, Connection pool ("Marc Mamin" <M.Mamin@intershop.de>) | 
| Ответы | Re: RESET ROLE and search_path, Connection pool | 
| Список | pgsql-general | 
On Fri, Dec 3, 2010 at 5:13 AM, Marc Mamin <M.Mamin@intershop.de> wrote:
Tangential to your question, but important:
Obviously each "user" could use RESET ROLE and become the super user.  This means that every piece of code that uses this pool needs to have security appropriate for code using the super user.  i.e. "Whatever, it's just using a read-only role, nothing bad can happen" is no longer a valid argument (if it ever was).Hello,
We are thinking about using a (java based) connection pool.
An issue is that there are many different users to connect.
My idea is to only have superuser connections in the pool
and change the connection role (with SET ROLE) each time
a user pick a connection there.
Tangential to your question, but important:
Do you have that much faith / trust in every "user"?
* "user" in quotes because I'm guessing you are referring to different portions of your application / application suite and hopefully not individual persons.
Derrick
В списке pgsql-general по дате отправления: