Re: [patch] plproxy v2

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: [patch] plproxy v2
Дата
Msg-id 28667.1216740357@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: [patch] plproxy v2  ("Marko Kreen" <markokr@gmail.com>)
Ответы Re: [patch] plproxy v2  (Hannu Krosing <hannu@krosing.net>)
Список pgsql-hackers
"Marko Kreen" <markokr@gmail.com> writes:
> And user can execute only pre-determines queries/functions on system2.

If that were actually the case then the security issue wouldn't loom
quite so large, but the dynamic_query example in the plproxy regression
tests provides a perfect example of how to ruin your security.

> Do you still see a big hole?

Truck-sized, at least.

The complaint here is not that it's impossible to use plproxy securely;
the complaint is that it's so very easy to use it insecurely.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Marko Kreen"
Дата:
Сообщение: Re: [patch] plproxy v2
Следующее
От: Simon Riggs
Дата:
Сообщение: Re: Schema-qualified statements in pg_dump output