Re: Security implications of config-file-location patch
От | Bruce Momjian |
---|---|
Тема | Re: Security implications of config-file-location patch |
Дата | |
Msg-id | 200410080421.i984L6w17451@candle.pha.pa.us обсуждение исходный текст |
Ответ на | Re: Security implications of config-file-location patch (Andrew Dunstan <andrew@dunslane.net>) |
Ответы |
Re: Security implications of config-file-location patch
|
Список | pgsql-hackers |
Andrew Dunstan wrote: > > > Tom Lane wrote: > > > > >I am sort of on the fence about this. I am thinking that it would be > >good to expose this information, but *only* to superusers. It would not > >take much code to add a GUC variable flag bit that prevents > >non-superusers from examining the value of the GUC variable, and only a > >little more code to reflect the correct paths into these variables all > >the time. > > > > > > > > > > On the basis that I can't see that anyone but the superuser has a > legitimate interest in the info, this sounds good. If they are using tablespaces is it OK that anyone can see their location? -- Bruce Momjian | http://candle.pha.pa.us pgman@candle.pha.pa.us | (610) 359-1001+ If your life is a hard drive, | 13 Roberts Road + Christ can be your backup. | Newtown Square, Pennsylvania19073
В списке pgsql-hackers по дате отправления: