pg.ddx.io  pgsql-admin@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Laurenz Albe <laurenz.albe@cybertec.at>
To: Sbob <sbob@quadratum-braccas.com>
To: David G. Johnston <david.g.johnston@gmail.com>
Cc: pgsql-admin@lists.postgresql.org
Subject: Re: Security definer function to alter a sequence
Date: Wed, 12 Feb 2025 08:36:01 +0100
Message-ID: <3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at> (raw)
In-Reply-To: <60f17e57-2549-442a-a11d-5e9ec63bd4eb@quadratum-braccas.com>
References: <9b25ab25-5c2c-440a-8bc5-ee77105387ff@quadratum-braccas.com>
	<CAKFQuwb63K0c7MyCSO+Skf3k9+3EgW-1mZcsVd3A88=Stx4Gdg@mail.gmail.com>
	<60f17e57-2549-442a-a11d-5e9ec63bd4eb@quadratum-braccas.com>

On Tue, 2025-02-11 at 15:57 -0700, Sbob wrote:
> I thought that DDL calls in a security definer function were blocked. I may be confused

I think you are.  I am not aware of anything that is forbidden in a SECURITY DEFINER
function.  On the contrary - people usually use them to perform activities that the
calling user is not allowed to do.

Don't forget to set a "search_path" on all SECURITY DEFINER functions.

Yours,
Laurenz Albe

-- 

*E-Mail Disclaimer*
Der Inhalt dieser E-Mail ist ausschliesslich fuer den 
bezeichneten Adressaten bestimmt. Wenn Sie nicht der vorgesehene Adressat 
dieser E-Mail oder dessen Vertreter sein sollten, so beachten Sie bitte, 
dass jede Form der Kenntnisnahme, Veroeffentlichung, Vervielfaeltigung oder 
Weitergabe des Inhalts dieser E-Mail unzulaessig ist. Wir bitten Sie, sich 
in diesem Fall mit dem Absender der E-Mail in Verbindung zu setzen.

*CONFIDENTIALITY NOTICE & DISCLAIMER
*This message and any attachment are 
confidential and may be privileged or otherwise protected from disclosure 
and solely for the use of the person(s) or entity to whom it is intended. 
If you have received this message in error and are not the intended 
recipient, please notify the sender immediately and delete this message and 
any attachment from your system. If you are not the intended recipient, be 
advised that any use of this message is prohibited and may be unlawful, and 
you must not copy this message or attachment or disclose the contents to 
any other person.





view thread (4+ messages)

Message-ID: <3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at>
Permalink:  ../3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at/
Also on:    postgresql.org/message-id/3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: laurenz.albe@cybertec.at, sbob@quadratum-braccas.com, david.g.johnston@gmail.com, pgsql-admin@lists.postgresql.org
  Subject: Re: Security definer function to alter a sequence
  In-Reply-To: <3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox