Re: Bugtraq: Having Fun With PostgreSQL - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Bugtraq: Having Fun With PostgreSQL
Date
Msg-id 1378.1182792712@sss.pgh.pa.us
Whole thread Raw
In response to Re: Bugtraq: Having Fun With PostgreSQL  (Andrew Sullivan <ajs@crankycanuck.ca>)
Responses Re: Bugtraq: Having Fun With PostgreSQL  (Andrew Sullivan <ajs@crankycanuck.ca>)
List pgsql-hackers
Andrew Sullivan <ajs@crankycanuck.ca> writes:
> To achieve the "secure by default" feature that you want (and I like
> the scare-quotes -- I agree with those that think this adds no real
> security, but I think you're right to worry about the perception
> angle in this case), why not have a ./configure option that sets the
> default trust level for the build?

Why is that better than the initdb-time option we already have?
Locking down options earlier rather than later is usually not a win.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Blowback from text conversion changes
Next
From: Tom Lane
Date:
Subject: Re: Frustrating issue with PGXS