Re: worried about PGPASSWORD drop - Mailing list pgsql-general

From Tom Lane
Subject Re: worried about PGPASSWORD drop
Date
Msg-id 20748.1030542404@sss.pgh.pa.us
Whole thread Raw
In response to worried about PGPASSWORD drop  (Christoph Dalitz <christoph.dalitz@hs-niederrhein.de>)
Responses Re: worried about PGPASSWORD drop  (Bruce Momjian <pgman@candle.pha.pa.us>)
List pgsql-general
Christoph Dalitz <christoph.dalitz@hs-niederrhein.de> writes:
> In the TODO list on http://developer.postgresql.org/todo.php,
> I found the following entry:
>  - Remove PGPASSWORD because it is insecure on some OS's, in 7.4
> Why?

I don't agree with removing the feature either, since it's perfectly
useful on many OSes.  However your assumption:

>  - The alternative (a new command line option for password)

is completely wrong; that is not the alternative being introduced.
See http://candle.pha.pa.us/main/writings/pgsql/sgml/libpq-envars.html

            regards, tom lane

pgsql-general by date:

Previous
From: Christoph Dalitz
Date:
Subject: worried about PGPASSWORD drop
Next
From: "Markus Wollny"
Date:
Subject: Naming-scheme for db-files