Re: Protection from SQL injection - Mailing list pgsql-hackers

From Josh Berkus
Subject Re: Protection from SQL injection
Date
Msg-id 200804291524.11565.josh@agliodbs.com
Whole thread Raw
In response to Re: Protection from SQL injection  (Andrew Sullivan <ajs@commandprompt.com>)
Responses Re: Protection from SQL injection  (Gregory Stark <stark@enterprisedb.com>)
List pgsql-hackers
> (I sort of like the
> suggestion up-thread, myself, which is to have a GUC that disables
> multi-statement commands.  That'd probably cover a huge number of
> cases, and combined with some sensible quoting rules in client
> libraries, would quite possibly be enough.)

MySQL did this already.

--
--Josh

Josh Berkus
PostgreSQL @ Sun
San Francisco


pgsql-hackers by date:

Previous
From: Andrew Sullivan
Date:
Subject: Re: Protection from SQL injection
Next
From: Andreas 'ads' Scherbaum
Date:
Subject: Re: Protection from SQL injection