Unix Technical Forum

BUG #2077: Hiding databases which I am not owner

This is a discussion on BUG #2077: Hiding databases which I am not owner within the pgsql Bugs forums, part of the PostgreSQL category; --> The following bug has been logged online: Bug reference: 2077 Logged by: Martin Pelikan Email address: martin.pelikan@gmail.com PostgreSQL version: ...


Go Back   Unix Technical Forum > Database Server Software > PostgreSQL > pgsql Bugs

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 04-10-2008, 10:31 AM
Martin Pelikan
 
Posts: n/a
Default BUG #2077: Hiding databases which I am not owner


The following bug has been logged online:

Bug reference: 2077
Logged by: Martin Pelikan
Email address: martin.pelikan@gmail.com
PostgreSQL version: 8.0.4
Operating system: Gentoo Linux 2.6.14-gentoo-r2
Description: Hiding databases which I am not owner
Details:

We have had on our old server (Debian Sarge) previous version of postgresql
database server (7.4.7) and if I logged in as normal user, I saw only my
database. Now we had to upgrade to gentoo ('cos debian is down) and I
decided to install new pgsql - 8.0.4 and if I log in (psql or phppgadmin), I
see all databases, not only my one.

I think it's a bug because of security - nosey people are everywhere...
And I want not to other people see how many users and databases are here -
server is half-public
Thank you for your reply - I found nowhere answer to my question

---------------------------(end of broadcast)---------------------------
TIP 4: Have you searched our list archives?

http://archives.postgresql.org

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 04-10-2008, 10:31 AM
Euler Taveira de Oliveira
 
Posts: n/a
Default Re: BUG #2077: Hiding databases which I am not owner

--- Martin Pelikan <martin.pelikan@gmail.com> escreveu:

> I think it's a bug because of security - nosey people are
> everywhere...

No. It's a feature.

> And I want not to other people see how many users and databases are
> here -
> server is half-public
>

See is one thing, access is another thing. We never hid databases and
other catalog objects. Instead we allow and deny access to this
databases. See pg_hba.conf documentation for information.



Euler Taveira de Oliveira
euler[at]yahoo_com_br








__________________________________________________ _____
Yahoo! doce lar. Faça do Yahoo! sua homepage.
http://br.yahoo.com/homepageset.html


---------------------------(end of broadcast)---------------------------
TIP 4: Have you searched our list archives?

http://archives.postgresql.org

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 05:42 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com