public inbox for [email protected]  
help / color / mirror / Atom feed
From: Andreas Joseph Krogh <[email protected]>
To: Christophe Pettus <[email protected]>
Cc: Tom Lane <[email protected]>
Cc: pgsql-general <[email protected]>
Cc: Greg Sabino Mullane <[email protected]>
Subject: Re: Effects of REVOKE SELECT ON ALL TABLES IN SCHEMA pg_catalog FROM PUBLIC
Date: Thu, 12 Sep 2024 16:13:26 +0200 (CEST)
Message-ID: <VisenaEmail.26.53346aad7e6ac25.191e693c3c9@origo-test01.app.internal.visena.net> (raw)
In-Reply-To: <[email protected]>
References: <VisenaEmail.0.81936c517b2d9cfe.191e44de951@origo-test01.app.internal.visena.net>
	<[email protected]>
	<VisenaEmail.1.4f10ceb0099d6ab1.191e48a6946@origo-test01.app.internal.visena.net>
	<CAKAnmm+SrS1=ggcc9qCAXd=uzJWzwH_CciM+aRr-PtDZjrEuRA@mail.gmail.com>
	<VisenaEmail.21.e9d63efdf68bfe51.191e663ceda@origo-test01.app.internal.visena.net>
	<CAKAnmm+ODqpCAF+jbqWaGRD8UBJhS66Us0deWQ01+PbOiS4L8A@mail.gmail.com>
	<[email protected]>



På torsdag 12. september 2024 kl. 16:10:26, skrev Christophe Pettus <
[email protected] <mailto:[email protected]>>:


> On Sep 12, 2024, at 06:58, Greg Sabino Mullane <[email protected]> wrote:
> 
> But if it works for you, go ahead. As Tom said, it will work 95% of the 
time. But it will break things that should work, and it will not prevent the 
ability to get the information in other ways. To be clear, we never recommend 
messing with the system catalogs, and this falls under the umbrella of messing 
with the system catalogs.

I can only echo that if the compliance people are taking a position that "you 
need to make an unsupported, ad-hoc modification to the database software's 
authentication system in order to meet this requirement," then the requirement 
is one that you should run, not walk, to get a waiver to, as that's a very 
unreasonable position for them to take.


We're probably going down the postgres_fdw route, that seems to do the job.






--
Andreas Joseph Krogh
CTO / Partner - Visena AS
Mobile: +47 909 56 963
[email protected] <mailto:[email protected]>
www.visena.com <https://www.visena.com;
 <https://www.visena.com;


view thread (3+ messages)

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: [email protected]
  Cc: [email protected], [email protected], [email protected], [email protected], [email protected]
  Subject: Re: Effects of REVOKE SELECT ON ALL TABLES IN SCHEMA pg_catalog FROM PUBLIC
  In-Reply-To: <VisenaEmail.26.53346aad7e6ac25.191e693c3c9@origo-test01.app.internal.visena.net>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox