Re: user-based query white list
От | Andrew Dunstan |
---|---|
Тема | Re: user-based query white list |
Дата | |
Msg-id | 493BFCA7.5010000@dunslane.net обсуждение исходный текст |
Ответ на | Re: user-based query white list (Andrew Chernow <ac@esilo.com>) |
Ответы |
Re: user-based query white list
Re: user-based query white list |
Список | pgsql-hackers |
Andrew Chernow wrote: > > I think what is missing is a way to deny the execution of queries that > don't operate on an object (like a table, sequence, role, schema, > etc...), OR queries not covered by the priv system. Object-based > queries can be locked down using the existing priv system. Not sure > if denying non-object related queries would work; what happens when > you call "SELECT NOW()" within an allowed function? > > What exactly are you trying to protect against? In general, my attitude is that databases should not allow direct access from untrusted sources. The API restriction you are talking about is something that is trivially easy to build into middleware, and only the middleware should be allowed access to the database. cheers andrew
В списке pgsql-hackers по дате отправления: