Re: Isn't pg_statistic a security hole? - Mailing list pgsql-hackers

From Jan Wieck
Subject Re: Isn't pg_statistic a security hole?
Date
Msg-id 200105071607.MAA02611@jupiter.jw.home
Whole thread Raw
In response to Re: Isn't pg_statistic a security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Tom Lane wrote:
> "Serguei Mokhov" <sa_mokho@alcor.concordia.ca> writes:
> > Being a simple user, I still want to view the stats from the table,
> > but it should be limited only to the stuff I own. I don't wanna let
> > others see any of my info, however.  The SU's, of course, should be
> > able to read all the stats.
>
> This is infeasible since we don't have a concept of per-row permissions.
> It's all or nothing.
   Can't   we   provide  a  view  that  shows  those  rows  from   pg_statistics that belong to the tables owned by the
current   user?
 


Jan

--

#======================================================================#
# It's easier to get forgiveness for being wrong than for being right. #
# Let's break this rule - forgive me.                                  #
#================================================== JanWieck@Yahoo.com #



_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



pgsql-hackers by date:

Previous
From: Vince Vielhaber
Date:
Subject: Re: typo in psql's help
Next
From: Bruce Momjian
Date:
Subject: Re: elog(LOG), elog(DEBUG)