BUG #1830: Non-super-user must be able to copy from a file - Mailing list pgsql-bugs

From Bernard
Subject BUG #1830: Non-super-user must be able to copy from a file
Date
Msg-id 20050817082216.8E7BAF0C12@svr2.postgresql.org
Whole thread Raw
Responses Re: BUG #1830: Non-super-user must be able to copy from a file  (Bruno Wolff III <bruno@wolff.to>)
List pgsql-bugs
The following bug has been logged online:

Bug reference:      1830
Logged by:          Bernard
Email address:      bht@actrix.gen.nz
PostgreSQL version: 8.0.3
Operating system:   Linux RedHat 9
Description:        Non-super-user must be able to copy from a file
Details:

On the attempt to bulk load a table from a file that is owned by the
non-superuser current database user, the following error message is
printed:

"must be superuser to COPY to or from a file"

What is the reason for this limitation?

It can't justifiably be for security reasons because if a web application
such as tomcat requires to bulk load tables automatically on a regular basis
then one would be forced to let the web application connect as superuser,
which is very bad for security.

In MySQL bulk loading works for all users.

We need a Postgresql solution.

We have a web application where both MySQL and Postresql are supported. With
Postgresql, the application would have to connect as user postgres. We have
to explain this security risk to our clients very clearly.

pgsql-bugs by date:

Previous
From: "Lee Hyun soon"
Date:
Subject: BUG #1829: pgsql odbc & ADO.NET(modify)
Next
From: Bruno Wolff III
Date:
Subject: Re: BUG #1830: Non-super-user must be able to copy from a file