Repository navigation
sec: 함수 기본권한 deny-by-default — 신설 함수 기본 ACL {postgres, service_role} 뿐 - #212
Merged
Merged
Conversation
edge_alert_fire(#210)의 재발 구조 차단. 운영 함수 기본권한이 새 public 함수에 authenticated EXECUTE 를 자동 부여해, service 전용 함수의 revoke 누락이 조용한 보안 구멍이 되는 구조였다. 20260920045336 이 테이블 T/T/R 에 한 조치의 함수판. 두 건인 이유(프로브 실측): 스키마 항목의 authenticated 를 걷어낸 뒤에도 신설 함수에 {=X, postgres, service_role} — 스키마 단위 기본권한은 내장 기본값 (PUBLIC=EXECUTE)에 더해질 뿐 못 걷어낸다. 내장을 바꾸는 유일한 레버인 전역(무스키마) 항목으로 PUBLIC 을 마저 제거했다. - 운영 적용 완료(20260929045320·20260929050613), 프로브 실측: public 신설 {postgres,service_role}(auth/anon=f), app 신설 {postgres} - 기존 함수 ACL 불변(기본권한은 미래 객체에만) — 주간 ⑭ 전항목 일치, 스냅샷은 바이트 불변(dump 가 ALTER DEFAULT PRIVILEGES 를 걸러냄 = CI 무영향) - 이후 규칙: 사용자용 RPC 신설 마이그레이션에 명시 grant 필수(기존 관례 그대로 — 누락의 실패 방향만 조용한 구멍 → 즉시 permission denied 로 반전) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
무엇이
#210(edge_alert_fire authenticated 구멍)의 재발 구조 차단. 운영
pg_default_acl이 새 public 함수에 authenticated EXECUTE 를 자동 부여하고 있었다 — service 전용 함수에서 revoke 를 잊으면 그대로 조용한 보안 구멍. 테이블 T/T/R 에 했던20260920045336과 같은 조치의 함수판.왜 두 건인가 (프로브 실측)
20260929045320: 스키마 항목에서 authenticated 제거. 그런데 프로브 결과 신설 함수가 여전히{=X, postgres, service_role}— 스키마 단위 기본권한은 내장 기본값(함수는 PUBLIC=EXECUTE)에 더해질 뿐 내장을 못 걷어낸다. 지금껏 안 터진 건 모든 함수 신설 마이그레이션이revoke from public을 명시한 관례 덕.20260929050613: 내장을 바꾸는 유일한 레버인 전역(무스키마) 항목으로 PUBLIC 제거.검증
{postgres=X, service_role=X}, auth/anon 실행 불가 · app 신설 →{postgres=X}_schema_dump.sh로 재덤프 diff 0 — 덤프가 ALTER DEFAULT PRIVILEGES 줄을 걸러내므로 pgtap·replay 무영향)이후 규칙
사용자용 RPC 신설 마이그레이션에 명시
grant execute … to authenticated필수(최근 마이그레이션 전부 이미 하던 관례). app 스키마 신설 함수를 RLS·invoker 경로에서 쓸 때도 동일. 누락의 실패 방향이 '조용한 구멍' → '앱에서 즉시 permission denied' 로 반전된다.🤖 Generated with Claude Code