Re: Wrong security context for deferred triggers? - Mailing list pgsql-hackers

From Tomas Vondra
Subject Re: Wrong security context for deferred triggers?
Date
Msg-id dede297a-3d24-7029-dfd9-06aeef8b9766@enterprisedb.com
Whole thread Raw
In response to Wrong security context for deferred triggers?  (Laurenz Albe <laurenz.albe@cybertec.at>)
Responses Re: Wrong security context for deferred triggers?
Re: Wrong security context for deferred triggers?
List pgsql-hackers
On 11/6/23 14:23, Laurenz Albe wrote:
> ...
> 
> This behavior looks buggy to me.  What do you think?
> I cannot imagine that it is a security problem, though.
> 

How could code getting executed under the wrong role not be a security
issue? Also, does this affect just the role, or are there some other
settings that may unexpectedly change (e.g. search_path)?


regards

-- 
Tomas Vondra
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company



pgsql-hackers by date:

Previous
From: Isaac Morland
Date:
Subject: Re: Wrong security context for deferred triggers?
Next
From: Stephen Frost
Date:
Subject: Re: Add the ability to limit the amount of memory that can be allocated to backends.