View Single Post

   
  #4 (permalink)  
Old 04-15-2008, 10:41 PM
Decibel!
 
Posts: n/a
Default Re: Problem with recent permission changes commits

On Mon, Aug 27, 2007 at 11:59:05AM -0700, Joshua D. Drake wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Decibel! wrote:
> > On Mon, Aug 27, 2007 at 08:08:34AM -0700, Joshua D. Drake wrote:

>
> >> This is a problem. Our analytics software purposefully does not use a
> >> super user, you are going to force the use of superusers with admin and
> >> monitoring tools.

> >
> > Well, you could always create a wrapper function that is SECURITY
> > DEFINER...

>
> Well from my perspective, it is nice that we don't have to install
> anything except a non privileged user to get what we need.
>
> Really, if we change this we might as well also block all access to
> information_schema, the net effect is the same.


Info_schema should be checking permissions the same as, say, \d does.

What I think we *really* need is a set of views for people to use that
have appropriate security, instead of using pg_catalog directly.
--
Decibel!, aka Jim Nasby decibel@decibel.org
EnterpriseDB http://enterprisedb.com 512.569.9461 (cell)

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.3 (FreeBSD)

iD8DBQFG0yeJdO30qud8SkgRAgAnAJ9jgiZVH45x0NTWJ2twKC 2O9pc6EQCgshtA
Jh7245CVeUM6STZx6U/LgPU=
=CC0P
-----END PGP SIGNATURE-----

Reply With Quote