Skip site navigation (1) Skip section navigation (2)

Re: pg_dump & ownership (again)

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Philip Warner <pjw(at)rhyme(dot)com(dot)au>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: pg_dump & ownership (again)
Date: 2000-08-01 19:49:16
Message-ID: 27782.965159356@sss.pgh.pa.us (view raw or flat)
Thread:
Lists: pgsql-hackers
Philip Warner <pjw(at)rhyme(dot)com(dot)au> writes:
> Recent testing of the BLOB restoration code of pg_dump has highlighted
> something that *may* be a problem, but I am not sure. BLOBs create tables,
> and AFAICT those tables are owned by the user who was connected at the
> time. This theoretically means that even though a user has access to a
> table with a BLOB column, they may not be able to read the BLOB - is that
> right? Should I worry about this?

The BLOB access code contains no permissions checks --- which is likely
a bug in itself, but anyway if you know the OID of a large object you
can do anything you want to it via the lo_xxx functions.

			regards, tom lane

In response to

Responses

pgsql-hackers by date

Next:From: Stephan SzaboDate: 2000-08-01 20:20:44
Subject: Re: random() function produces wrong range
Previous:From: Tom LaneDate: 2000-08-01 18:33:18
Subject: Re: random() function produces wrong range

Privacy Policy | About PostgreSQL
Copyright © 1996-2014 The PostgreSQL Global Development Group