Re: error in trigger creation - Mailing list pgsql-general

From Tom Lane
Subject Re: error in trigger creation
Date
Msg-id 2858912.1713734480@sss.pgh.pa.us
Whole thread Raw
In response to Re: error in trigger creation  (Adrian Klaver <adrian.klaver@aklaver.com>)
Responses Re: error in trigger creation
List pgsql-general
Adrian Klaver <adrian.klaver@aklaver.com> writes:
> On 4/21/24 11:20, yudhi s wrote:
>> So in this case i was wondering if "event trigger" can cause any 
>> additional threat and thus there is no such privilege like "create 
>> trigger" exist in postgres and so it should be treated cautiously?

> An event trigger runs as a superuser and executes a function that in 
> turn can do many things, you do the math on the threat level.

As a trivial example: an event trigger could prevent the legitimate
superuser(s) from doing anything at all in that database, just by
blocking all their commands.  This might not even require malicious
intent, merely faulty coding --- but the opportunity for malicious
intent is staggeringly large.

            regards, tom lane



pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: query multiple schemas
Next
From: Ron Johnson
Date:
Subject: CLUSTER vs. VACUUM FULL