Re: Isn't pg_statistic a security hole? - Mailing list pgsql-hackers

From Stephan Szabo
Subject Re: Isn't pg_statistic a security hole?
Date
Msg-id Pine.BSF.4.21.0105061101530.73009-100000@megazone23.bigpanda.com
Whole thread Raw
In response to Re: Isn't pg_statistic a security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: Isn't pg_statistic a security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
On Sun, 6 May 2001, Tom Lane wrote:

> "Serguei Mokhov" <sa_mokho@alcor.concordia.ca> writes:
> > Being a simple user, I still want to view the stats from the table,
> > but it should be limited only to the stuff I own. I don't wanna let
> > others see any of my info, however.  The SU's, of course, should be
> > able to read all the stats.
> 
> This is infeasible since we don't have a concept of per-row permissions.
> It's all or nothing.

Maybe make statistics readable only by superusers with a view that uses
CURRENT_USER or something like that to only give the objects that
have owners of this user?  Might be an ugly view, but...




pgsql-hackers by date:

Previous
From: Lincoln Yeoh
Date:
Subject: Re: Re: New Linux xfs/reiser file systems
Next
From: "Serguei Mokhov"
Date:
Subject: Fw: Isn't pg_statistic a security hole?