Re: elog(FATAL)ing non-existent roles during client

Поиск
Список
Период
Сортировка
От Gavin Sherry
Тема Re: elog(FATAL)ing non-existent roles during client
Дата
Msg-id Pine.LNX.4.58.0612050019320.18986@linuxworld.com.au
обсуждение исходный текст
Ответ на Re: elog(FATAL)ing non-existent roles during client authentication  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: elog(FATAL)ing non-existent roles during client  (Gavin Sherry <swm@linuxworld.com.au>)
Список pgsql-hackers
On Thu, 30 Nov 2006, Tom Lane wrote:

> Gavin Sherry <swm@linuxworld.com.au> writes:
> > I wonder if we should check if the role exists for the other
> > authentication methods too? get_role_line() should be very cheap and it
> > would prevent unnecessary authentication work if we did it before
> > contacting, for example, the client ident server. Even with trust, it
> > would save work because otherwise we do not check if the user exists until
> > InitializeSessionUserId(), at which time we're set up our proc entry etc.
>
> This only saves work if the supplied ID is in fact invalid, which one
> would surely think isn't the normal case; otherwise it costs more.

Yes.

> I could see doing this in the ident path, because contacting a remote
> ident server is certainly expensive on both sides.  I doubt it's a good
> idea in the trust case.

Agreed. How about Kerberos too, applying the same logic?

Gavin


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Pavel Stehule"
Дата:
Сообщение: SQL/PSM implemenation for PostgreSQL (roadmap)
Следующее
От: Oleg Bartunov
Дата:
Сообщение: Fix for 8.2 release. Was: [GENERAL] Problems to create the portuguese dictionary