security_definer_search_path GUC

Поиск
Список
Период
Сортировка
От Marko Tiikkaja
Тема security_definer_search_path GUC
Дата
Msg-id CAL9smLA_SEWvpusSR8B+K=OOhMwRfKHABZB7J3rc_WcZDmroHQ@mail.gmail.com
обсуждение исходный текст
Ответы Re: security_definer_search_path GUC
Список pgsql-hackers
Hi,

Since writing SECURITY DEFINER functions securely requires annoying incantations[1], wouldn't it be nice if we provided a way for the superuser to override the default search path via a GUC in postgresql.conf?  That way you can set search_path if you want to override the default, but if you leave it out you're not vulnerable, assuming security_definer_search_path only contains secure schemas.


.m

В списке pgsql-hackers по дате отправления: