Re: AW: [PATCH] Re: Setuid functions - Mailing list pgsql-hackers

From Mark Volpe
Subject Re: AW: [PATCH] Re: Setuid functions
Date
Msg-id 3B373A5F.15FD771@epa.gov
Whole thread Raw
In response to AW: [PATCH] Re: Setuid functions  (Zeugswetter Andreas SB <ZeugswetterA@wien.spardat.at>)
List pgsql-hackers
Actually, I liked the SET AUTHORIZATION { DEFINER | INVOKER } terminology
mentioned earlier.

Mark

Zeugswetter Andreas SB wrote:
> 
> > > This patch will implement the "ENABLE PRIVILEGE" and "DISABLE PRIVILEGE"
> > > commands   in PL/pgSQL, which, respectively, change the effective uid to that
> > > of the function owner and back. It doesn't break security (I hope). The
> > > commands can be abbreviated as "ENABLE" and "DISABLE" for the poor saps that
> 
> Anybody else want to object to this abbreviation idea ? Seems
> reading ENABLE; or DISABLE; is very hard to interpret in source code
> (enable what ?) and should thus not be allowed (or allow "ENABLE PRIV").
> 
> Andreas
> 
> ---------------------------(end of broadcast)---------------------------
> TIP 3: if posting/reading through Usenet, please send an appropriate
> subscribe-nomail command to majordomo@postgresql.org so that your
> message can get through to the mailing list cleanly


pgsql-hackers by date:

Previous
From: Jan Wieck
Date:
Subject: Re: Setuid functions
Next
From: Tom Lane
Date:
Subject: Re: AW: [PATCH] Re: Setuid functions