Re: BUG #16447: The query field of the pg_stat_activity tabledisplays the clear text of the password.

Поиск
Список
Период
Сортировка
От Magnus Hagander
Тема Re: BUG #16447: The query field of the pg_stat_activity tabledisplays the clear text of the password.
Дата
Msg-id CABUevEz3rSA8OvNfO1uy1OxXJ+fm4brfBFqaWu4bJcr8W8CxNg@mail.gmail.com
обсуждение исходный текст
Ответ на BUG #16447: The query field of the pg_stat_activity table displays the clear text of the password.  (PG Bug reporting form <noreply@postgresql.org>)
Список pgsql-bugs
On Mon, May 18, 2020 at 11:41 AM PG Bug reporting form <noreply@postgresql.org> wrote:
The following bug has been logged on the website:

Bug reference:      16447
Logged by:          yi Ding
Email address:      abcxiaod@126.com
PostgreSQL version: 10.12
Operating system:   linux
Description:       

When the administrator create a user and set the password,  we can see the
password in the pg_stat_activity table.


Not when the administrator uses the suggested method for setting passwords. You can use \passwd in psql or use the createuser command to avoid that. This is clearly documented on the CREATE ROLE documentation page in the Notes section (https://www.postgresql.org/docs/12/sql-createrole.html)

--

В списке pgsql-bugs по дате отправления:

Предыдущее
От: PG Bug reporting form
Дата:
Сообщение: BUG #16451: .psql_history file shows clear text password.
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: BUG #16449: Log file and the query field of thepg_stat_statements table display clear text password.