Re: Granting SET and ALTER SYSTE privileges for GUCs - Mailing list pgsql-hackers

From David G. Johnston
Subject Re: Granting SET and ALTER SYSTE privileges for GUCs
Date
Msg-id CAKFQuwa2dZx5h=XSGPb3kBpHHMcLvkdpm-xcUnqVpnMP1yAZfg@mail.gmail.com
Whole thread Raw
In response to Re: Granting SET and ALTER SYSTE privileges for GUCs  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
On Wed, Mar 30, 2022 at 8:46 AM Tom Lane <tgl@sss.pgh.pa.us> wrote: 
I don't want to do that with
a blunderbuss, but perhaps there's an argument to do it for specific
cases (search_path comes to mind, though the performance cost could be
significant, since I think setting that in function SET clauses is
common).
 

I suspect it became considerably moreso when we fixed the search_path CVE since we basically told people that doing so, despite the possible performance hit, was the easiest solution to their immediate dump/restore failures.  But ISTM that because that SET has a function invocation context it could bypass any such check.  Though maybe the DO command exposes a flaw in that idea.
David J.

pgsql-hackers by date:

Previous
From: Andres Freund
Date:
Subject: Re: Adding CI to our tree
Next
From: Greg Stark
Date:
Subject: Re: Frontend error logging style