]> granicus.if.org Git - postgresql/commit
I've attached the fixed version of the patch below. After the
authorBruce Momjian <bruce@momjian.us>
Fri, 7 Sep 2001 22:02:32 +0000 (22:02 +0000)
committerBruce Momjian <bruce@momjian.us>
Fri, 7 Sep 2001 22:02:32 +0000 (22:02 +0000)
commit1834987fb6b705ec37abdb5a2804d79761f7fa56
tree19130f88398a62be0d047ba2d3e4731443cc7470
parentbd9b32803bee2a85e41deb5e546c3b0e16912e2b
I've attached the fixed version of the patch below.  After the
discussion on pgsql-hackers (especially the frightening memory dump in
<12273.999562219@sss.pgh.pa.us>), we decided that it is best not to
use identifiers from an untrusted source at all.  Therefore, all
claims of the suitability of PQescapeString() for identifiers have
been removed.

Florian Weimer
doc/src/sgml/libpq.sgml
src/interfaces/libpq/fe-exec.c
src/interfaces/libpq/libpq-fe.h