Re: [HACKERS] LISTEN/NOTIFY Security and the docs

2012-08-29 Thread Bruce Momjian
On Thu, May 24, 2012 at 01:03:18PM +0200, Magnus Hagander wrote: > On Fri, May 18, 2012 at 5:08 PM, Chander Ganesan wrote: > > Hi All, > > > > I just realized that anyone can listen for notifications (using listen) so > > long as they know the "channel" name.  This means that a user could receive

Re: [HACKERS] LISTEN/NOTIFY Security and the docs

2012-05-24 Thread Magnus Hagander
On Fri, May 18, 2012 at 5:08 PM, Chander Ganesan wrote: > Hi All, > > I just realized that anyone can listen for notifications (using listen) so > long as they know the "channel" name.  This means that a user could receive > and view the payload for another user. > > Perhaps it would be good to no

[HACKERS] LISTEN/NOTIFY Security and the docs

2012-05-18 Thread Chander Ganesan
Hi All, I just realized that anyone can listen for notifications (using listen) so long as they know the "channel" name. This means that a user could receive and view the payload for another user. Perhaps it would be good to note this in the documentation (i.e., there should be no expectati