Re: Isn't pg_statistic a security hole?

From: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Isn't pg_statistic a security hole?
Date: 2001-05-07 23:02:08
Message-ID: 200105072302.f47N28v08423@candle.pha.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

> > I doubt it is worth letting non-super users see values in that table.
> > Their only value is in debugging the optimizer, which seems like a
> > super-user job anyway.
>
> Well, mumble. I routinely ask people who're complaining of bad plans
> for extracts from their pg_statistic table. I don't foresee that need
> vanishing any time soon :-(. The idea of a view seemed nice, in part
> because it could be set up to give all the useful info with a simple
>
> select * from pg_statview where relname = 'foo';
>
> rather than the messy three-way join you have to type now.

Sounds fine, but aren't most people who we ask for stats superusers?

--
Bruce Momjian | http://candle.pha.pa.us
pgman(at)candle(dot)pha(dot)pa(dot)us | (610) 853-3000
+ If your life is a hard drive, | 830 Blythe Avenue
+ Christ can be your backup. | Drexel Hill, Pennsylvania 19026

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Bruce Momjian 2001-05-07 23:07:06 Re: Re: New Linux xfs/reiser file systems
Previous Message Tom Lane 2001-05-07 22:54:21 Re: Isn't pg_statistic a security hole?