Re: Increasing security in a shared environment ... - Mailing list pgsql-hackers

From Dave Page
Subject Re: Increasing security in a shared environment ...
Date
Msg-id 50000.80.177.99.193.1080583873.squirrel@ssl.vale-housing.co.uk
Whole thread Raw
In response to Re: Increasing security in a shared environment ...  (Euler Taveira de Oliveira <euler@ufgnet.ufg.br>)
Responses Re: Increasing security in a shared environment ...  ("Marc G. Fournier" <scrappy@postgresql.org>)
List pgsql-hackers
It's rumoured that Euler Taveira de Oliveira once said:
> Hi Christopher,
>
>> > "The \l command should only list databases that the current user is
>> > authorized for, the \du command should only list users authorized
>> > for the current database (and perhaps only superusers should get
>> > even that much information), etc.  Perhaps it is possible to set PG
>> > to do this, but that should probably be the default."
>> >
> Seem reasonable. Why not prevent normal users to dig on the pg_catalog?
> What is the impact of it?

Because they can't use tools like pgAdmin or phpPgAdmin unless they can at
least read all the catalogs.
Regards, Dave




pgsql-hackers by date:

Previous
From: "Marc G. Fournier"
Date:
Subject: Re: Increasing security in a shared environment ...
Next
From: Tom Lane
Date:
Subject: Re: Increasing security in a shared environment ...