Re: proposal: psql \setfileref
От | Pavel Stehule |
---|---|
Тема | Re: proposal: psql \setfileref |
Дата | |
Msg-id | CAFj8pRAuev1+MxJCjJDr1q-E_1OgwxnP_4keJrRaTuwQt4n_JA@mail.gmail.com обсуждение исходный текст |
Ответ на | Re: proposal: psql \setfileref (Gilles Darold <gilles.darold@dalibo.com>) |
Ответы |
Re: proposal: psql \setfileref
Re: proposal: psql \setfileref |
Список | pgsql-hackers |
hi
2016-10-04 9:18 GMT+02:00 Gilles Darold <gilles.darold@dalibo.com>:
Le 03/10/2016 à 23:23, Gilles Darold a écrit :
> Le 03/10/2016 à 23:03, Robert Haas a écrit :
>> On Mon, Oct 3, 2016 at 3:54 PM, Gilles Darold <gilles@darold.net> wrote:
>>> 4) An other problem is that like this this patch will allow anyone to upload into a
>>> column the content of any system file that can be read by postgres system user
>>> and then allow non system user to read its content.
>> I thought this was a client-side feature, so that it would let a
>> client upload any file that the client can read, but not things that
>> can only be read by the postgres system user.
>>
> Yes that's right, sorry for the noise, forget this fourth report.
>
After some more though there is still a security issue here. For a
PostgreSQL user who also have login acces to the server, it is possible
to read any file that the postgres system user can read, especially a
.pgpass or a recovery.conf containing password.
here is new update - some mentioned issues are fixed + regress tests and docs
regards
Pavel
--
Gilles Darold
Consultant PostgreSQL
http://dalibo.com - http://dalibo.org
--
Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-hackers
Вложения
В списке pgsql-hackers по дате отправления: