Re: About "ERROR: must be *superuser* to COPY to or from a file" - Mailing list pgsql-general

From John D. Burger
Subject Re: About "ERROR: must be *superuser* to COPY to or from a file"
Date
Msg-id 1485292af0b2c75064d5ee609b7fdd77@mitre.org
Whole thread Raw
In response to Re: About "ERROR: must be *superuser* to COPY to or from a file"  (Greg Stark <gsstark@mit.edu>)
Responses Re: About "ERROR: must be *superuser* to COPY to or from a file"  (Greg Stark <gsstark@mit.edu>)
List pgsql-general
>> Well, they would have access to every world readable file on the
>> system, ie /etc, /usr, /lib, ... most files are world readable.
>> There's
>> a lot of discussion about this, yet no-one has demonstrated that COPY
>> FROM STDIN isn't just as good and avoids all the issues entirely.
>
> Well they're world-readable. So, uh, huh?

I haven't completely followed the details of this, but I took the point
to be that the files might be readable for anyone with a real account
on the server machine, but that doesn't mean they should be accessible
to every remote DB user.

- John Burger
   MITRE



pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: stack depth limit exceeded
Next
From: Jamie Deppeler
Date:
Subject: Re: stack depth limit exceeded