Re: security label support, part.2

Поиск
Список
Период
Сортировка
От Robert Haas
Тема Re: security label support, part.2
Дата
Msg-id AANLkTimMzCagPgVZgve7yD1UK_CapSiXjn=pBFbYiGhQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: security label support, part.2  (Stephen Frost <sfrost@snowman.net>)
Ответы Re: security label support, part.2  (Stephen Frost <sfrost@snowman.net>)
Re: security label support, part.2  (Tom Lane <tgl@sss.pgh.pa.us>)
Re: security label support, part.2  (KaiGai Kohei <kaigai@ak.jp.nec.com>)
Список pgsql-hackers
On Tue, Aug 17, 2010 at 1:50 PM, Stephen Frost <sfrost@snowman.net> wrote:
> No..  and I'm not sure we ever would.  What we *have* done is removed
> all permissions checking on child tables when a parent is being
> queried..

Yeah.  I'm not totally sure that is sensible for a MAC environment.
Heck, it's arguably incorrect (though perhaps quite convenient) in a
DAC environment.  Anyway, I wonder if it would be sensible to try to
adjust the structure of the DAC permissions checks so enhanced
security providers can make their own decision about how to handle
this case.

--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise Postgres Company


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Stephen Frost
Дата:
Сообщение: Re: Progress indication prototype
Следующее
От: "Erik Rijkers"
Дата:
Сообщение: Re: Progress indication prototype