Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uN6NA-00BnN9-T9 for pgsql-general@arkaria.postgresql.org; Thu, 05 Jun 2025 08:54:53 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1uN6N8-0067BY-UN for pgsql-general@arkaria.postgresql.org; Thu, 05 Jun 2025 08:54:51 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uN6N8-0067BP-GY for pgsql-general@lists.postgresql.org; Thu, 05 Jun 2025 08:54:51 +0000 Received: from mail-ed1-x52a.google.com ([2a00:1450:4864:20::52a]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1uN6N3-000Ll7-37 for pgsql-general@lists.postgresql.org; Thu, 05 Jun 2025 08:54:46 +0000 Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-604f5691bceso1284091a12.0 for ; Thu, 05 Jun 2025 01:54:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=peoplecall-com.20230601.gappssmtp.com; s=20230601; t=1749113683; x=1749718483; darn=lists.postgresql.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=XJy8cpXgUgMFcxC+ZrjZWpTHAe3qz2m7XzgSZhP5TjI=; b=y7VKKcEKL00FzAL/8F4oqwQnARGiUkENuo9wLUdaD6Ep/M79vRyCuZyxekcz5Rbilm kKI5uLIWi/iT7jFZ8vsgtUid7XxrzqnyhV7VQ61dG/orPrBnyLJPk8S1gnJSfSxsGJwo F1ILG5jX7JFzpv0VbU3aEdc3UzJROhmktLMdQfeMhUzAP486GEan0D7MEjWHSFMyklVd vYiHtcGrBZKjnmdzl9Gb90sdHLMO3ewVXnvL/PMvXwTJcFrBpz1HkutT+s8LGdch/kv1 Gf08h2+CTjZ+debCucera1mWTsG5ZSTBurHoRYSsPlbk7LH9IDPkVC6btiyAs0BW83zR T+NA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1749113683; x=1749718483; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=XJy8cpXgUgMFcxC+ZrjZWpTHAe3qz2m7XzgSZhP5TjI=; b=GANbR3AY1nFTZDAI9MZrkR2Zv9rM3Alaxdk7MbTaKDCElcxAdPK43QiSsBVO+TR4JD QRoYBdtu5amDsbCy2hmBMJGgfaxLGgqdhoxQhsNkHClgDoZZ9rgeacnRoBmq8e+dF7t3 9WfWuEHQ9aKpmRxeOfMM0RZwa3oxJOE4LJI0jNZMrnrvzs6zTfuTkABBEqszFnH9LW62 OG9UQ3lNf4DcXoYdmKDZDCMzDeJ1F3GR7Hv3qihUnkrgpcVHUL5tmtuGOSKELg/hxlyQ 4xUjRWQSfIqNWfjVZmAjL04eGYh0ScC2hPJNNISMwwRrQdw23+rFnpDiUNFOUMEgwafN U35A== X-Forwarded-Encrypted: i=1; AJvYcCWHVdovwyOIkbaItL7s9pRwZZn+ant7xuNYOopAsB5kQc9fDB4mIAtvBrJOuGxNe4VYKerK7pk5dpM5kGSc@lists.postgresql.org X-Gm-Message-State: AOJu0YyfcofCDTj0tzHngt0sX2kFGGvit9OABz99LfnmfzmciTszupx8 vjKtWHtEx75mXV/oaI6gMb8b6awIGshwUTo/guH4CoTdaFRDEjQJK4vcBLOgkhFg0yNjHAkIOgI J4TockPyeXM2HI3MycuEwTtADZwwj1rbmKGJr083Z X-Gm-Gg: ASbGncsflgu1/9T36ijhMwDVZIS4j+NhF9GgQVpYvdeM6e2gSmKH9ITdQEVBCHR2iLE GDPr1D3JKV6Jq279pLlGgvG2tX6UsCdoA+x6v4qrxTfJyMq7b5Nc+dh2DdibF/UEZbySleXo+Gs tUm0TZRVFiEOf3luvIRlZwFofvaxPQdw== X-Google-Smtp-Source: AGHT+IH8x0ysRLAumlBBJem6V10vyc/jSUERLNAwjXM/sYWSmDladv0ifAow8+0k+9bK+fRHW9HWiXIpYodCYCiHCYw= X-Received: by 2002:a05:6402:3496:b0:602:4405:777b with SMTP id 4fb4d7f45d1cf-606ea3c47d2mr5743026a12.24.1749113682691; Thu, 05 Jun 2025 01:54:42 -0700 (PDT) MIME-Version: 1.0 References: <1079732.1749078352@sss.pgh.pa.us> In-Reply-To: <1079732.1749078352@sss.pgh.pa.us> From: Francisco Olarte Date: Thu, 5 Jun 2025 10:54:05 +0200 X-Gm-Features: AX0GCFsnM66tWi1a0gb8rIhCwvsHb6i8_1BnK1eoy3ezneimTxCgcqS0xsHi-A4 Message-ID: Subject: Re: Feature request: Settings to disable comments and multiple statements in a connection To: Tom Lane Cc: Glen K , "pgsql-general@lists.postgresql.org" Content-Type: text/plain; charset="UTF-8" List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, 5 Jun 2025 at 01:06, Tom Lane wrote: > ... An injection attack is normally > trying to break out of a quoted string, not a comment. I think the comments he refers to are more used to do "bobby tables" like stuff, as helpers in correct statement forming, not to inject per se. ( I do not think the feature request is worth doing either, just commenting ). Francisco Olarte.