From: Laurenz Albe <laurenz.albe@cybertec.at>
To: Sbob <sbob@quadratum-braccas.com>
To: David G. Johnston <david.g.johnston@gmail.com>
Cc: pgsql-admin@lists.postgresql.org
Subject: Re: Security definer function to alter a sequence
Date: Wed, 12 Feb 2025 08:36:01 +0100
Message-ID: <3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at> (raw)
In-Reply-To: <60f17e57-2549-442a-a11d-5e9ec63bd4eb@quadratum-braccas.com>
References: <9b25ab25-5c2c-440a-8bc5-ee77105387ff@quadratum-braccas.com>
<CAKFQuwb63K0c7MyCSO+Skf3k9+3EgW-1mZcsVd3A88=Stx4Gdg@mail.gmail.com>
<60f17e57-2549-442a-a11d-5e9ec63bd4eb@quadratum-braccas.com>
On Tue, 2025-02-11 at 15:57 -0700, Sbob wrote:
> I thought that DDL calls in a security definer function were blocked. I may be confused
I think you are. I am not aware of anything that is forbidden in a SECURITY DEFINER
function. On the contrary - people usually use them to perform activities that the
calling user is not allowed to do.
Don't forget to set a "search_path" on all SECURITY DEFINER functions.
Yours,
Laurenz Albe
--
*E-Mail Disclaimer*
Der Inhalt dieser E-Mail ist ausschliesslich fuer den
bezeichneten Adressaten bestimmt. Wenn Sie nicht der vorgesehene Adressat
dieser E-Mail oder dessen Vertreter sein sollten, so beachten Sie bitte,
dass jede Form der Kenntnisnahme, Veroeffentlichung, Vervielfaeltigung oder
Weitergabe des Inhalts dieser E-Mail unzulaessig ist. Wir bitten Sie, sich
in diesem Fall mit dem Absender der E-Mail in Verbindung zu setzen.
*CONFIDENTIALITY NOTICE & DISCLAIMER
*This message and any attachment are
confidential and may be privileged or otherwise protected from disclosure
and solely for the use of the person(s) or entity to whom it is intended.
If you have received this message in error and are not the intended
recipient, please notify the sender immediately and delete this message and
any attachment from your system. If you are not the intended recipient, be
advised that any use of this message is prohibited and may be unlawful, and
you must not copy this message or attachment or disclose the contents to
any other person.
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-admin@postgresql.org
Cc: laurenz.albe@cybertec.at, sbob@quadratum-braccas.com, david.g.johnston@gmail.com, pgsql-admin@lists.postgresql.org
Subject: Re: Security definer function to alter a sequence
In-Reply-To: <3fc539fbd75c0634f31ead1d84f383b37ae19a34.camel@cybertec.at>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox