Skip site navigation (1) Skip section navigation (2)

Peripheral Links

Header And Logo

PostgreSQL
| The world's most advanced open source database.

Site Navigation

Search for
  Advanced Search

Re: How to allow users to log on only from my application


  • From: Raymond O'Donnell <rod(at)iol(dot)ie>
  • To: Andrus <kobruleht2(at)hot(dot)ee>, 'PostgreSQL' <pgsql-general(at)postgresql(dot)org>
  • Subject: Re: How to allow users to log on only from my application
  • Date: Tue, 30 Jan 2007 00:29:24 +0000
  • Message-id: <45BE9164(dot)5020007(at)iol(dot)ie>

Andrus wrote:

My application implements field and row level security.
I have custom table of users where user privileges are described.

However user can login directly to database using pgAdmin. This bypasses
the security.

How to allow users to login only from my application ?
I think I must create server-side pgsql procedure for login validation.

What role are your users using to login via PgAdmin? Why not simply deny them access in pg_hba.conf?

Ray.


---------------------------------------------------------------
Raymond O'Donnell, Director of Music, Galway Cathedral, Ireland
rod(at)iol(dot)ie
---------------------------------------------------------------



Home | Main Index | Thread Index

Privacy Policy | PostgreSQL Archives hosted by Command Prompt, Inc. | Designed by tinysofa
Copyright © 1996 – 2008 PostgreSQL Global Development Group