Limit global default function execution privileges - Mailing list pgsql-hackers

From David G. Johnston
Subject Limit global default function execution privileges
Date
Msg-id CAKFQuwYWpSxjar5rXDuDf4Ubb7CXsgTXd0Na8xoO+kccMmdwVg@mail.gmail.com
Whole thread Raw
Responses Re: Limit global default function execution privileges  (Stephen Frost <sfrost@snowman.net>)
List pgsql-hackers
Since we are discussing locking down our defaults is revoking the global function execution privilege granted to PUBLIC - instead limiting it to just the pg_catalog schema - on the table?

I'm not sure how strongly I feel toward the proposal but it does come up on these lists; and the fact that it doesn't distinguish between security definer and security invoker is a trap for the unaware.

David J.

pgsql-hackers by date:

Previous
From: Stephen Frost
Date:
Subject: Re: public schema default ACL
Next
From: "Bossart, Nathan"
Date:
Subject: Re: BUG #14941: Vacuum crashes