Is PQfn() insecure or not?

Поиск
Список
Период
Сортировка
От ljb
Тема Is PQfn() insecure or not?
Дата
Msg-id autddu$2uri$1@news.hub.org
обсуждение исходный текст
Ответы Re: Is PQfn() insecure or not?  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-interfaces
"Programmer's Guide, Client Interfaces, libpq, The Fast-Path Interface"
describes PQfn() and has this alarming remark:
 "This is a trapdoor into system internals and can be a potential  security hole."

Sure this isn't true. PQfn() just lets a frontend call a function which is
also accessible (if maybe not useful) via a SELECT statement, correct?  If
I'm right, we should remove the scary language from the documentation.  If
on the other hand PQfn() is a security hole, could someone post an exploit?


В списке pgsql-interfaces по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: PGLOG problem
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Is PQfn() insecure or not?