Re: pg_stat_statements: password in command is not obfuscated

Поиск
Список
Период
Сортировка
От David Rowley
Тема Re: pg_stat_statements: password in command is not obfuscated
Дата
Msg-id CAKJS1f95_peGgpUgeG6nJ7Y4KzhcG07jdbwfM_8D4fRrCbUhmg@mail.gmail.com
обсуждение исходный текст
Ответ на pg_stat_statements: password in command is not obfuscated  (legrand legrand <legrand_legrand@hotmail.com>)
Ответы Re: pg_stat_statements: password in command is not obfuscated
Список pgsql-general
On 24 March 2018 at 10:30, legrand legrand <legrand_legrand@hotmail.com> wrote:
> It seems that passwords used in commands are not removed when caught by
> pg_stat_statements
> (they are not "normalized" being utility statements)
>
> exemple:
> alter role tt with password '123';
>
> select query from public.pg_stat_statements
> where query like '%password%';
>
> query
> ----------------------------------------
> alter role tt with password '123';
>
> Do you think its a bug ?

If it is, then it's not a bug in pg_stat_statements. log_statement =
'ddl' would have kept a record of the same thing.

Perhaps the best fix would be a documentation improvement to mention
the fact and that it's best not to use plain text passwords in
CREATE/ALTER ROLE. Passwords can be md5 encrypted.

-- 
 David Rowley                   http://www.2ndQuadrant.com/
 PostgreSQL Development, 24x7 Support, Training & Services


В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: FDW Foreign Table Access: strange LOG message
Следующее
От: HORDER Phil
Дата:
Сообщение: RE: primary key and unique index