public inbox for [email protected]  
help / color / mirror / Atom feed
Broken behavior after minor update CVE-2024-10978
2+ messages / 2 participants
[nested] [flat]

* Broken behavior after minor update CVE-2024-10978
@ 2024-11-18 12:17  Антон Глушаков <[email protected]>
  0 siblings, 1 reply; 2+ messages in thread

From: Антон Глушаков @ 2024-11-18 12:17 UTC (permalink / raw)
  To: [email protected]

After upgrading to version 14.14, the behavior of roles related to the "set
role" option broke.
We actively use the feature "alter user <username> set role db_role"
in order to automatically change the role context upon login.
But now this behavior has changed, and the context does not change, which
unfortunately breaks all role-based access to data.

If this was an abnormal behavior, is there an alternative way to
automatically change the role context when connecting to the DB?


^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: Broken behavior after minor update CVE-2024-10978
@ 2024-11-19 15:31  David G. Johnston <[email protected]>
  parent: Антон Глушаков <[email protected]>
  0 siblings, 0 replies; 2+ messages in thread

From: David G. Johnston @ 2024-11-19 15:31 UTC (permalink / raw)
  To: Антон Глушаков <[email protected]>; +Cc: [email protected]

On Tue, Nov 19, 2024 at 8:26 AM Антон Глушаков <[email protected]>
wrote:

> After upgrading to version 14.14, the behavior of roles related to the
> "set role" option broke.
>

Correct.  A proper bug report was already filed and this has been fixed in
this week's out-of-band update.

David J.


^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2024-11-19 15:31 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-11-18 12:17 Broken behavior after minor update CVE-2024-10978 Антон Глушаков <[email protected]>
2024-11-19 15:31 ` David G. Johnston <[email protected]>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox