Re: Is this a bug, possible security hole, or wrong - Mailing list pgsql-general

From Tom Lane
Subject Re: Is this a bug, possible security hole, or wrong
Date
Msg-id 18875.1023975836@sss.pgh.pa.us
Whole thread Raw
In response to Re: Is this a bug, possible security hole, or wrong  (Mike Mascari <mascarm@mascari.com>)
List pgsql-general
Mike Mascari <mascarm@mascari.com> writes:
> If a user has permissions to write PL/SQL functions, and the statistics
> collector is running with STATS_COMMAND_STRING = true, could not that
> user "log" other users' queries using the same technique I described by
> querying pg_stat_activity?

Not unless he's superuser.

            regards, tom lane

pgsql-general by date:

Previous
From: Mike Mascari
Date:
Subject: Re: Is this a bug, possible security hole, or wrong
Next
From: Thomas Lockhart
Date:
Subject: Re: automatic time zone conversion