From: | "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com> |
---|---|
To: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
Cc: | Joseph S <jks(at)selectacast(dot)net>, pgsql general list <pgsql-general(at)postgresql(dot)org> |
Subject: | Re: [ANNOUNCE] == PostgreSQL Weekly News - August 26 2007 == |
Date: | 2007-08-27 16:04:53 |
Message-ID: | 46D2F625.90104@commandprompt.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-announce pgsql-general |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Tom Lane wrote:
> Joseph S <jks(at)selectacast(dot)net> writes:
>>> Tom Lane committed:
>>> - Restrict pg_relation_size to relation owner, pg_database_size to DB
>>> owner, and pg_tablespace_size to superusers. Perhaps we could
>>> weaken the first case to just require SELECT privilege, but that
>>> doesn't work for the other cases, so use ownership as the common
>>> concept.
>>>
>> Is there going to be a way to turn this off easily?
>
> No. If you want to make an argument for weaker restrictions than these,
> argue away, but security restrictions that can be "easily turned off"
> are no security at all.
Sure, but you haven't made a security adjustment. You have made a
behavioral adjustment that is guaranteed to break remote applications.
Joshua D. Drake
>
> regards, tom lane
>
> ---------------------------(end of broadcast)---------------------------
> TIP 2: Don't 'kill -9' the postmaster
>
- --
=== The PostgreSQL Company: Command Prompt, Inc. ===
Sales/Support: +1.503.667.4564 24x7/Emergency: +1.800.492.2240
PostgreSQL solutions since 1997 http://www.commandprompt.com/
UNIQUE NOT NULL
Donate to the PostgreSQL Project: http://www.postgresql.org/about/donate
PostgreSQL Replication: http://www.commandprompt.com/products/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFG0vYlATb/zqfZUUQRAj+9AJ9Mz7tXXgrtibJMY/WLmL7x3wja3gCeP0Kw
gi91a+6oxgT+ziI9mwLHlfI=
=wxN+
-----END PGP SIGNATURE-----
From | Date | Subject | |
---|---|---|---|
Next Message | Joseph S | 2007-08-27 17:34:43 | Re: [ANNOUNCE] == PostgreSQL Weekly News - August 26 2007 == |
Previous Message | Tom Lane | 2007-08-27 15:40:18 | Re: [ANNOUNCE] == PostgreSQL Weekly News - August 26 2007 == |
From | Date | Subject | |
---|---|---|---|
Next Message | Jonah H. Harris | 2007-08-27 16:08:17 | Re: [HACKERS] Undetected corruption of table files |
Previous Message | Jeff Amiel | 2007-08-27 16:04:30 | Re: Out of Memory - 8.2.4 |