3 ms·
One suggestion is to allow further segregation of permissions for functions like SLEEP, BENCHMARK, etc. A front-end request has no need for it. It’s the exposi
by cottenio 8y ago
One suggestion is to allow further segregation of permissions for functions like SLEEP, BENCHMARK, etc. A front-end request has no need for it.
It’s the exposition of things that “act” on lax query permission sets that “appear” read-only (but in fact have interrupt style executions) that leads to trivialization of abuse.
- JetSpiegel 8y agoEven better is to whitelist all SQL than runs on the database using prepared statements. Anything else is a hack.