Re: Facility for detecting insecure object naming - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Facility for detecting insecure object naming
Date
Msg-id 32760.1533741090@sss.pgh.pa.us
Whole thread Raw
In response to Re: Facility for detecting insecure object naming  (Mark Dilger <hornschnorter@gmail.com>)
List pgsql-hackers
Mark Dilger <hornschnorter@gmail.com> writes:
> On Aug 8, 2018, at 7:47 AM, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>> The advantage of a function trust mechanism is that it'd provide
>> security against calling functions you didn't intend to without
>> any visible changes in normal application behavior.  The security
>> team gave up on that approach because it seemed too complicated to
>> pursue as a secretly-developed security patch, but I still think
>> it's the right long-term answer.

> Do you have a WIP patch partially developed for this?  If it is no
> longer secret, perhaps the rest of us could take a look?

Yeah, I do have a POC prototype, let me blow the dust off it ...

            regards, tom lane


pgsql-hackers by date:

Previous
From: Alvaro Herrera
Date:
Subject: Re: Typo in doc or wrong EXCLUDE implementation
Next
From: "Bossart, Nathan"
Date:
Subject: Re: Improve behavior of concurrent TRUNCATE