Unix Technical Forum

Re: prevent users from seeing pl/pgsql code in pgadmin

This is a discussion on Re: prevent users from seeing pl/pgsql code in pgadmin within the pgsql Interfaces Pgadmin Hackers forums, part of the PostgreSQL category; --> > -----Original Message----- > From: Dave Page [mailto:dpage@vale-housing.co.uk] > Sent: Wednesday, March 16, 2005 12:06 PM > To: Merlin ...


Go Back   Unix Technical Forum > Database Server Software > PostgreSQL > pgsql Interfaces Pgadmin Hackers

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 04-17-2008, 04:34 PM
Merlin Moncure
 
Posts: n/a
Default Re: prevent users from seeing pl/pgsql code in pgadmin



> -----Original Message-----
> From: Dave Page [mailto:dpage@vale-housing.co.uk]
> Sent: Wednesday, March 16, 2005 12:06 PM
> To: Merlin Moncure
> Cc: pgadmin-hackers@postgresql.org
> Subject: RE: [pgadmin-hackers] prevent users from seeing pl/pgsql code

in
> pgadmin
>
>
>
> > -----Original Message-----
> > From: Merlin Moncure [mailto:merlin.moncure@rcsonline.com]
> > Sent: 16 March 2005 16:54
> > To: Dave Page
> > Cc: pgadmin-hackers@postgresql.org
> > Subject: RE: [pgadmin-hackers] prevent users from seeing
> > pl/pgsql code in pgadmin
> >
> > > > I also tried hacking the search path and putting a pg_proc table

> > into
> > > > the public schema. While this fixed select * from pg_proc
> > > > (but not /df),
> > > > pgAdmin still pulled the function source.
> > >
> > > Odd - it didn't here. Every query on pg_proc resulted in a

> > message box
> > > telling me it couldn't select from pg_proc - protecting the

source,
> > but
> > > breaking pgAdmin.

> >
> > What did you do exactly? Here's what I tried:

>


Ah. Ok, yes this certainly breaks pgAdmin. And true function code
protection on the server side seems pretty nasty without some serious
hacking.

What about this: do think pgAdmin should prevent rendering the sql code
for various database schema objects (but especially functions) if the
pgAdmin user does not have appropriate access to that object?

For example, if user does not have the 'execute' permission, disable sql
render of the function object. I think this is pretty reasonable from a
security standpoint until such time that the server gets this
capability.

Merlin

---------------------------(end of broadcast)---------------------------
TIP 3: if posting/reading through Usenet, please send an appropriate
subscribe-nomail command to majordomo@postgresql.org so that your
message can get through to the mailing list cleanly

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 08:43 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com