Re: BUG #13651: trigger security invoker attack

From: 德哥 <digoal(at)126(dot)com>
To: "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>
Cc: "pgsql-bugs(at)postgresql(dot)org" <pgsql-bugs(at)postgresql(dot)org>
Subject: Re: BUG #13651: trigger security invoker attack
Date: 2015-09-30 07:02:41
Message-ID: 1ad9dff4.9584.1501d0f6c58.Coremail.digoal@126.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

HI,
If we can change the function's security dynamical, like :
When function trigged in trigger or rule, force these function's security = table,mview,view's owner.
There will no risks in the case.

PS: MySQL do that.

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message marc hamelin 2015-09-30 10:48:47 postgresql 9.4 with nested "order by"
Previous Message 德哥 2015-09-30 05:19:46 Re: BUG #13651: trigger security invoker attack