Re: [PATCH] Largeobject access controls - Mailing list pgsql-hackers

From KaiGai Kohei
Subject Re: [PATCH] Largeobject access controls
Date
Msg-id 4A9C5FDA.9040905@ak.jp.nec.com
Whole thread Raw
In response to Re: [PATCH] Largeobject access controls  (Alvaro Herrera <alvherre@commandprompt.com>)
Responses Re: [PATCH] Largeobject access controls  (KaiGai Kohei <kaigai@ak.jp.nec.com>)
List pgsql-hackers
Alvaro Herrera wrote:
> Tom Lane wrote:
>> KaiGai Kohei <kaigai@kaigai.gr.jp> writes:
>>> BTW, currently, the default ACL of largeobject allows anything for owner
>>> and nothing for world. Do you have any comment for the default behavior?
>> Mph.  I think the backlash will be too great.  You have to leave the
>> default behavior the same as it is now, ie, world access.
> 
> BTW as a default it is pretty bad.  Should we have a GUC var to set the
> default LO permissions?

It seems to me a reasonable idea in direction.
However, it might be better to add a GUC variable to turn on/off LO
permission feature, not only default permissions.
It allows us to control whether the privilege mechanism should perform
in backward compatible, or not.
-- 
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai@ak.jp.nec.com>


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: remove flatfiles.c
Next
From: "Joshua D. Drake"
Date:
Subject: Re: 8.5 release timetable, again