mirror of
				https://github.com/postgres/postgres.git
				synced 2025-10-31 10:30:33 +03:00 
			
		
		
		
	Harden hstore_plperl, hstore_plpython, and ltree_plpython against search-path-based attacks by using @extschema:name@ notation to refer to the underlying hstore or ltree data type. This allows removal of the previous documentation warning suggesting that they must be installed in the same schema as the underlying data type. In passing, also improve a para in extend.sgml to suggest using @extschema:name@ for such purposes. Discussion: https://postgr.es/m/692480.1736021695@sss.pgh.pa.us
		
			
				
	
	
		
			20 lines
		
	
	
		
			807 B
		
	
	
	
		
			SQL
		
	
	
	
	
	
			
		
		
	
	
			20 lines
		
	
	
		
			807 B
		
	
	
	
		
			SQL
		
	
	
	
	
	
| /* contrib/hstore_plpython/hstore_plpython3u--1.0.sql */
 | |
| 
 | |
| -- complain if script is sourced in psql, rather than via CREATE EXTENSION
 | |
| \echo Use "CREATE EXTENSION hstore_plpython3u" to load this file. \quit
 | |
| 
 | |
| CREATE FUNCTION hstore_to_plpython3(val internal) RETURNS internal
 | |
| LANGUAGE C STRICT IMMUTABLE
 | |
| AS 'MODULE_PATHNAME', 'hstore_to_plpython';
 | |
| 
 | |
| CREATE FUNCTION plpython3_to_hstore(val internal) RETURNS @extschema:hstore@.hstore
 | |
| LANGUAGE C STRICT IMMUTABLE
 | |
| AS 'MODULE_PATHNAME', 'plpython_to_hstore';
 | |
| 
 | |
| CREATE TRANSFORM FOR @extschema:hstore@.hstore LANGUAGE plpython3u (
 | |
|     FROM SQL WITH FUNCTION hstore_to_plpython3(internal),
 | |
|     TO SQL WITH FUNCTION plpython3_to_hstore(internal)
 | |
| );
 | |
| 
 | |
| COMMENT ON TRANSFORM FOR @extschema:hstore@.hstore LANGUAGE plpython3u IS 'transform between hstore and Python dict';
 |