pg_duckdb icon indicating copy to clipboard operation
pg_duckdb copied to clipboard

security: GUC to block access to local filesystem

Open wuputah opened this issue 6 months ago • 5 comments

Discussed this a long time ago... but currently we allow DuckDB to read from the local filesystem. This is a security risk; the CSV reader is particularly easy to use here since it will read just about any plain text file.

This should instead be controllable via a GUC, default disabled, that can only be enabled by superuser.

wuputah avatar Aug 07 '24 21:08 wuputah