From 147f2e916c16590b2c9762ec370f226c0e4ae043 Mon Sep 17 00:00:00 2001
From: Bruce Momjian
Date: Sat, 6 Jan 2007 21:58:22 +0000
Subject: [PATCH] Add:
> o Consider parsing the -c string into individual queries so each
> is run in its own transaction
>
> o Consider disallowing multiple queries in PQexec() as an
> additional barrier to SQL injection attacks
---
doc/TODO | 9 +++++++--
doc/src/FAQ/TODO.html | 14 ++++++++------
2 files changed, 15 insertions(+), 8 deletions(-)
diff --git a/doc/TODO b/doc/TODO
index 5661f18728..f5e1ea472d 100644
--- a/doc/TODO
+++ b/doc/TODO
@@ -2,7 +2,7 @@
PostgreSQL TODO List
====================
Current maintainer: Bruce Momjian (bruce@momjian.us)
-Last updated: Sat Jan 6 15:00:41 EST 2007
+Last updated: Sat Jan 6 16:33:48 EST 2007
The most recent version of this document can be viewed at
http://www.postgresql.org/docs/faqs.TODO.html.
@@ -738,6 +738,9 @@ Clients
because setting the transaction isolation level must be the
first statement of a transaction.
+ o Consider parsing the -c string into individual queries so each
+ is run in its own transaction
+
* pg_dump
@@ -795,8 +798,10 @@ Clients
held on the server waiting for them to be requested by libpq.
One complexity is that a statement like SELECT 1/col could error
out mid-way through the result set.
- * Fix SSL retry to avoid useless repeated connection attempts and
+ o Fix SSL retry to avoid useless repeated connection attempts and
ensuing misleading error messages
+ o Consider disallowing multiple queries in PQexec() as an
+ additional barrier to SQL injection attacks
Triggers
diff --git a/doc/src/FAQ/TODO.html b/doc/src/FAQ/TODO.html
index 0f0c98f4d9..4d1a64da60 100644
--- a/doc/src/FAQ/TODO.html
+++ b/doc/src/FAQ/TODO.html
@@ -8,7 +8,7 @@
Current maintainer: Bruce Momjian (bruce@momjian.us)
-Last updated: Sat Jan 6 15:00:41 EST 2007
+Last updated: Sat Jan 6 16:33:48 EST 2007
The most recent version of this document can be viewed at
http://www.postgresql.org/docs/faqs.TODO.html.
@@ -669,6 +669,8 @@ first.
because setting the transaction isolation level must be the
first statement of a transaction.
+ Consider parsing the -c string into individual queries so each
+ is run in its own transaction
pg_dump
@@ -721,12 +723,12 @@ first.
held on the server waiting for them to be requested by libpq.
One complexity is that a statement like SELECT 1/col could error
out mid-way through the result set.
-
- - Fix SSL retry to avoid useless repeated connection attempts and
+
- Fix SSL retry to avoid useless repeated connection attempts and
ensuing misleading error messages
-
+ Consider disallowing multiple queries in PQexec() as an
+ additional barrier to SQL injection attacks
-
+
-
+