diff options
| author | Tom Lane | 2010-09-25 19:57:05 +0000 |
|---|---|---|
| committer | Tom Lane | 2010-09-25 20:20:50 +0000 |
| commit | 2c875a1deaba78d04e749397b630073d7723c476 (patch) | |
| tree | 338d4b67c5d8b2eac44ed9baea957e2dfeb10a55 /doc/FAQ_DEV | |
| parent | 9825ad9f4fd2da51e6decbf62c55023cec09fa43 (diff) | |
Further fixes to the pg_get_expr() security fix in back branches.
It now emerges that the JDBC driver expects to be able to use pg_get_expr()
on an output of a sub-SELECT. So extend the check logic to be able to recurse
into a sub-SELECT to see if the argument is ultimately coming from an
appropriate column. Per report from Thomas Kellerer.
Diffstat (limited to 'doc/FAQ_DEV')
0 files changed, 0 insertions, 0 deletions
