Re: Isn't pg_statistic a security hole?

Поиск
Список
Период
Сортировка
От Stephan Szabo
Тема Re: Isn't pg_statistic a security hole?
Дата
Msg-id Pine.BSF.4.21.0105061101530.73009-100000@megazone23.bigpanda.com
обсуждение исходный текст
Ответ на Re: Isn't pg_statistic a security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Isn't pg_statistic a security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
On Sun, 6 May 2001, Tom Lane wrote:

> "Serguei Mokhov" <sa_mokho@alcor.concordia.ca> writes:
> > Being a simple user, I still want to view the stats from the table,
> > but it should be limited only to the stuff I own. I don't wanna let
> > others see any of my info, however.  The SU's, of course, should be
> > able to read all the stats.
> 
> This is infeasible since we don't have a concept of per-row permissions.
> It's all or nothing.

Maybe make statistics readable only by superusers with a view that uses
CURRENT_USER or something like that to only give the objects that
have owners of this user?  Might be an ugly view, but...




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Lincoln Yeoh
Дата:
Сообщение: Re: Re: New Linux xfs/reiser file systems
Следующее
От: "Serguei Mokhov"
Дата:
Сообщение: Fw: Isn't pg_statistic a security hole?