Re: PQescapeIdentifier

Поиск
Список
Период
Сортировка
От Dave Page
Тема Re: PQescapeIdentifier
Дата
Msg-id E7F85A1B5FF8D44C8A1AF6885BC9A0E4013885A1@ratbert.vale-housing.co.uk
обсуждение исходный текст
Ответ на PQescapeIdentifier  (Christopher Kings-Lynne <chris.kings-lynne@calorieking.com>)
Список pgsql-hackers

> -----Original Message-----
> From: pgsql-hackers-owner@postgresql.org
> [mailto:pgsql-hackers-owner@postgresql.org] On Behalf Of
> Christopher Kings-Lynne
> Sent: 31 May 2006 04:16
> To: Tom Lane
> Cc: Hackers
> Subject: Re: [HACKERS] PQescapeIdentifier
>
> > Christopher Kings-Lynne <chris.kings-lynne@calorieking.com> writes:
> >> Here's a question. I wish to add a function to libpq to escape
> >> PostgreSQL identifiers.  Will this function be subject to the same
> >> security/encoding issues as PQescapeString?
> >
> > Is this of any general-purpose use?  How many apps are
> really prepared
> > to let an untrusted user dictate which columns are
> selected/compared?
>
> phpPgAdmin has use for it, I assume pgAdmin would as well.

Yes, it would.

Regards, Dave.


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Martijn van Oosterhout
Дата:
Сообщение: Re: plperl's ppport.h out of date?
Следующее
От: "Magnus Hagander"
Дата:
Сообщение: Re: [PATCHES] Magic block for modules