From: | Itagaki Takahiro <itagaki(dot)takahiro(at)gmail(dot)com> |
---|---|
To: | Magnus Hagander <magnus(at)hagander(dot)net> |
Cc: | Josh Berkus <josh(at)agliodbs(dot)com>, PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: pg_stat_replication security |
Date: | 2011-01-17 11:11:04 |
Message-ID: | AANLkTinoQRNWL4X8dhfAvbciejMzL5m0bnJ-knAKguHJ@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
On Mon, Jan 17, 2011 at 19:51, Magnus Hagander <magnus(at)hagander(dot)net> wrote:
> Here's a patch that limits it to superuser only. We can't easily match
> it to the user of the session given the way the walsender data is
> returned - it doesn't contain the user information. But limiting it to
> superuser only seems perfectly reasonable and in line with the
> encouragement not to use the replication user for login.
>
> Objections?
It hides all fields in pg_stat_wal_senders(). Instead, can we just
revoke usage of the function and view? Or, do we have some plans
to add fields which normal users can see?
--
Itagaki Takahiro
From | Date | Subject | |
---|---|---|---|
Next Message | Andrew Dunstan | 2011-01-17 11:26:59 | Re: Warning compiling pg_dump (MinGW, Windows XP) |
Previous Message | Joel Jacobson | 2011-01-17 11:01:52 | Re: Bug in pg_describe_object, patch v2 |