| From: | Alvaro Herrera <alvherre(at)commandprompt(dot)com> |
|---|---|
| To: | Dave Page <dpage(at)pgadmin(dot)org> |
| Cc: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Lars Olson <leolson1(at)uiuc(dot)edu>, pgsql-bugs(at)postgresql(dot)org |
| Subject: | Re: BUG #4074: Using SESSION_USER or CURRENT_USER in a view definition is unsafe |
| Date: | 2008-03-31 22:22:47 |
| Message-ID: | 20080331222247.GI24048@alvh.no-ip.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-bugs pgsql-www |
Dave Page wrote:
> On Mon, Mar 31, 2008 at 10:46 PM, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
> > If this were a security issue, you already spilled the beans by
> > reporting it to a public mailing list; so I'm unsure what you are
> > concerned about.
>
> I'd wager that Lars didn't realise the bug form goes straight to the
> list. We should probably make that more clear.
>
> On the other hand it does say to report security issues to security(at)(dot)(dot)(dot)
Let's have a checkbox "I am reporting a security issue" and send the
mail to security@ if checked.
--
Alvaro Herrera http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.
| From | Date | Subject | |
|---|---|---|---|
| Next Message | uri | 2008-04-01 08:47:25 | BUG #4075: PostgreSQL Database Server 8.2 failed to start |
| Previous Message | Dave Page | 2008-03-31 22:04:25 | Re: BUG #4074: Using SESSION_USER or CURRENT_USER in a view definition is unsafe |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Bruce Momjian | 2008-04-02 02:40:03 | varadic patch |
| Previous Message | Dave Page | 2008-03-31 22:04:25 | Re: BUG #4074: Using SESSION_USER or CURRENT_USER in a view definition is unsafe |