babelfish-for-postgresql / babelfish_extensions

Babelfish for PostgreSQL provides the capability for PostgreSQL to work with applications written for Microsoft SQL Server. Babelfish understands the SQL Server wire-protocol and T-SQL, the Microsoft SQL Server query and procedural language, so you don’t have to switch database drivers or rewrite all of your application queries.
https://babelfishpg.org/
Apache License 2.0
265 stars 87 forks source link

Fix permission leak in sys.database_principals #2672

Open thephantomthief opened 2 weeks ago

thephantomthief commented 2 weeks ago

Description

Currently, sys.database_principals T-SQL view shows all the T-SQL users irrespective of the current user. The expectation is that current user should only be able to see the system users and users it has permission of.

This commit fixes the sys.database_principals view to align with the expected T-SQL behaviour.

Task: BABEL-4935 Signed-off-by: Sharu Goel goelshar@amazon.com

Test Scenarios Covered

Check List

By submitting this pull request, I confirm that my contribution is under the terms of the Apache 2.0 and PostgreSQL licenses, and grant any person obtaining a copy of the contribution permission to relicense all or a portion of my contribution to the PostgreSQL License solely to contribute all or a portion of my contribution to the PostgreSQL open source project.

For more information on following Developer Certificate of Origin and signing off your commits, please check here.

coveralls commented 2 weeks ago

Pull Request Test Coverage Report for Build 9577113926

Details


Totals Coverage Status
Change from base Build 9568439596: 0.0%
Covered Lines: 42079
Relevant Lines: 57371

💛 - Coveralls