Re: W3C Specs: Web SQL
От | Alvaro Herrera |
---|---|
Тема | Re: W3C Specs: Web SQL |
Дата | |
Msg-id | 1289231570-sup-7471@alvh.no-ip.org обсуждение исходный текст |
Ответ на | W3C Specs: Web SQL (Charles Pritchard <chuck@jumis.com>) |
Ответы |
Re: W3C Specs: Web SQL
Re: W3C Specs: Web SQL |
Список | pgsql-hackers |
Excerpts from Charles Pritchard's message of sáb nov 06 23:20:13 -0300 2010: > Simple async sql sub-set (the spec in trouble): > http://dev.w3.org/html5/webdatabase/ This is insane. This spec allows the server to run arbitrary SQL commands on the client, AFAICT. That seems like infinite joy for malicious people running webservers. The more powerful the dialect of SQL the client implements, the more dangerous it is. -- Álvaro Herrera <alvherre@commandprompt.com> The PostgreSQL Company - Command Prompt, Inc. PostgreSQL Replication, Consulting, Custom Development, 24x7 support
В списке pgsql-hackers по дате отправления: