Skip to content

Commit 40d1a10

Browse files
committed
Doc: stop implying recommendation of insecure search_path value.
SQL "SET search_path = 'pg_catalog, pg_temp'" is silently equivalent to "SET search_path = pg_temp, pg_catalog, "pg_catalog, pg_temp"" instead of the intended "SET search_path = pg_catalog, pg_temp". (The intent was a two-element search path. With the single quotes, it instead specifies one element with a comma and a space in the middle of the element.) In addition to the SET statement, this affects SET clauses of CREATE FUNCTION, ALTER ROLE, and ALTER DATABASE. It does not affect the set_config() SQL function. Though the documentation did not show an insecure command, remove single quotes that could entice a reader to write an insecure command. Back-patch to v13 (all supported versions). Reported-by: Sven Klemm <sven@timescale.com> Author: Sven Klemm <sven@timescale.com> Backpatch-through: 13
1 parent 18dc43a commit 40d1a10

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

doc/src/sgml/extend.sgml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1339,8 +1339,8 @@ SELECT * FROM pg_extension_update_paths('<replaceable>extension_name</replaceabl
13391339
secure <varname>search_path</varname>; do <emphasis>not</emphasis>
13401340
trust the path provided by <command>CREATE/ALTER EXTENSION</command>
13411341
to be secure. Best practice is to temporarily
1342-
set <varname>search_path</varname> to <literal>'pg_catalog,
1343-
pg_temp'</literal> and insert references to the extension's
1342+
set <varname>search_path</varname> to <literal>pg_catalog,
1343+
pg_temp</literal> and insert references to the extension's
13441344
installation schema explicitly where needed. (This practice might
13451345
also be helpful for creating views.) Examples can be found in
13461346
the <filename>contrib</filename> modules in

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy