Re: Generating unique session ids - Mailing list pgsql-general

From Joshua D. Drake
Subject Re: Generating unique session ids
Date
Msg-id 44C8DE66.60207@commandprompt.com
Whole thread Raw
In response to Re: Generating unique session ids  (Alvaro Herrera <alvherre@commandprompt.com>)
List pgsql-general
Alvaro Herrera wrote:
> Tom Lane wrote:
>
>>> * Any database user is most of the time able to read function
>>> bodies, so anybody who is able co connect to your database will be
>>> able to get your 'secret_salt' and then predict session id's.
>> Yeah, it's not clear where to hide the secret.
>
> In a memfrob'ed (or something better probably) area in a C function?

You could also do it in a untrusted plperl or plpython function.

Joshua D. Drake




--

    === The PostgreSQL Company: Command Prompt, Inc. ===
Sales/Support: +1.503.667.4564 || 24x7/Emergency: +1.800.492.2240
    Providing the most comprehensive  PostgreSQL solutions since 1997
              http://www.commandprompt.com/



pgsql-general by date:

Previous
From: "Weiss, Kevin"
Date:
Subject: Update entire column with new date values
Next
From: Richard Huxton
Date:
Subject: Re: Permissions to connect to postgres database