Re: Trusted versus untrusted Pl language

2020-12-24 Thread Stephen Frost
Greetings, * Steven Pousty (steve.pou...@gmail.com) wrote: > If you consider the application developer or data scientist's perspective > it makes total sense. I don't like the pattern of appdevs always working as > the postgres user, it encourages bad patterns and can often blow up when > you

Re: Trusted versus untrusted Pl language

2020-12-24 Thread Steven Pousty
Ok David but that is not what I have heard from a lot of other people in the PostgreSQL community. On Thu, Dec 24, 2020 at 1:26 PM David G. Johnston < david.g.johns...@gmail.com> wrote: > On Thu, Dec 24, 2020 at 1:01 PM Steven Pousty > wrote: > >> The SQL I am talking about is this: >> UPDATE

Re: Trusted versus untrusted Pl language

2020-12-24 Thread David G. Johnston
On Thu, Dec 24, 2020 at 1:01 PM Steven Pousty wrote: > The SQL I am talking about is this: > UPDATE pg_language SET lanpltrusted = true WHERE lanname LIKE 'plr'; > You seem to be missing the point. The language is either trusted, or it's not. Modifying the catalogs is not part of a "good

Re: Trusted versus untrusted Pl language

2020-12-24 Thread Steven Pousty
On Wed, Dec 23, 2020 at 4:49 PM Bruce Momjian wrote: > On Wed, Dec 23, 2020 at 07:38:16PM -0500, Tom Lane wrote: > > Steven Pousty writes: > > > 3. An example of how to make a pre-installed untrusted langue into a > > > trusted language > > > > Under what circumstances would that be a good

Re: Trusted versus untrusted Pl language

2020-12-23 Thread Bruce Momjian
On Wed, Dec 23, 2020 at 07:38:16PM -0500, Tom Lane wrote: > Steven Pousty writes: > > 3. An example of how to make a pre-installed untrusted langue into a > > trusted language > > Under what circumstances would that be a good idea? > > I can't imagine that we'd really want to recommend end

Re: Trusted versus untrusted Pl language

2020-12-23 Thread Tom Lane
Steven Pousty writes: > 3. An example of how to make a pre-installed untrusted langue into a > trusted language Under what circumstances would that be a good idea? I can't imagine that we'd really want to recommend end users doing that, but an example would surely be taken as a recommendation

Re: Trusted versus untrusted Pl language

2020-12-23 Thread Steven Pousty
On Wed, Dec 23, 2020 at 2:41 PM Bruce Momjian wrote: > On Wed, Dec 23, 2020 at 08:24:13PM +, PG Doc comments form wrote: > > The following documentation comment has been logged on the website: > > > > Page: https://www.postgresql.org/docs/13/plpython.html > > Description: > > > > Hey all: >

Re: Trusted versus untrusted Pl language

2020-12-23 Thread Bruce Momjian
On Wed, Dec 23, 2020 at 08:24:13PM +, PG Doc comments form wrote: > The following documentation comment has been logged on the website: > > Page: https://www.postgresql.org/docs/13/plpython.html > Description: > > Hey all: > This page & the PL/PERL page are the closest I have seen in the

Trusted versus untrusted Pl language

2020-12-23 Thread PG Doc comments form
The following documentation comment has been logged on the website: Page: https://www.postgresql.org/docs/13/plpython.html Description: Hey all: This page & the PL/PERL page are the closest I have seen in the docs about trusted versus untrusted languages. It would be great if we could add a