pgsql: Document search_path security with untrusted dbowner or CREATERO

Поиск
Список
Период
Сортировка
От Noah Misch
Тема pgsql: Document search_path security with untrusted dbowner or CREATERO
Дата
Msg-id E1ie1xt-0006j0-4F@gemulon.postgresql.org
обсуждение исходный текст
Список pgsql-committers
Document search_path security with untrusted dbowner or CREATEROLE.

Commit 5770172cb0c9df9e6ce27c507b449557e5b45124 wrote, incorrectly, that
certain schema usage patterns are secure against CREATEROLE users and
database owners.  When an untrusted user is the database owner or holds
CREATEROLE privilege, a query is secure only if its session started with
SELECT pg_catalog.set_config('search_path', '', false) or equivalent.
Back-patch to 9.4 (all supported versions).

Discussion: https://postgr.es/m/20191013013512.GC4131753@rfd.leadboat.com

Branch
------
REL_11_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/b97857b67659afda917bef87ac03bb99781db878

Modified Files
--------------
doc/src/sgml/ddl.sgml | 80 +++++++++++++++++++++++++--------------------------
1 file changed, 40 insertions(+), 40 deletions(-)


В списке pgsql-committers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: pgsql: Doc: improve documentation about run-time pruning's effects on E
Следующее
От: Amit Kapila
Дата:
Сообщение: pgsql: Fix typos in miscinit.c.