Re: Temporary Views - Mailing list pgsql-hackers

From Bruce Momjian
Subject Re: Temporary Views
Date
Msg-id 200208132243.g7DMhVY23820@candle.pha.pa.us
Whole thread Raw
In response to Re: Temporary Views  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: Temporary Views  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Tom Lane wrote:
> Hannu Krosing <hannu@tm.ee> writes:
> > It seems to be a broken view not security risk in 7.2.1
> 
> The implementation of temp tables has changed completely in CVS tip,
> so experiments with 7.2 aren't very relevant.  In CVS tip I believe
> you *could* read the contents of someone else's temp table, assuming
> you had permissions to read the view.  However, you'd not be guaranteed
> to get up-to-date information, since the guy who actually owns the temp
> table would be using his local-buffer manager for access to it; there
> might be many pages that you'd see stale information from because the
> only up-to-date copy is in local memory of the owning backend.
> 
> I see some potential for confusion here, but not really any
> crash-the-database scenarios.  I also do not see a security risk:
> you did grant the other guy read permission on your view, after all.

Does every other user see the view name on his temp table?  Can two
people create a view on a temp table at the same time?  It seems not:test=> create temp table x1(x int);CREATE
TABLEtest=>create view x2 as select * from x1;ERROR:  Relation 'x2' already exist
 

Seems this should work.

--  Bruce Momjian                        |  http://candle.pha.pa.us pgman@candle.pha.pa.us               |  (610)
359-1001+  If your life is a hard drive,     |  13 Roberts Road +  Christ can be your backup.        |  Newtown Square,
Pennsylvania19073
 


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Temporary Views
Next
From: Tom Lane
Date:
Subject: Re: Temporary Views