Document security implications of check_function_bodies.

Back-patch to 8.4 (all supported versions).
This commit is contained in:
Noah Misch 2014-02-17 09:33:31 -05:00
parent 823b9dc256
commit 09e2d4c145

View File

@ -3967,9 +3967,11 @@ COPY postgres_log FROM '/full/path/to/logfile.csv' WITH csv;
This parameter is normally on. When set to <literal>off</>, it
disables validation of the function body string during <xref
linkend="sql-createfunction"
endterm="sql-createfunction-title">. Disabling validation is
occasionally useful to avoid problems such as forward references
when restoring function definitions from a dump.
endterm="sql-createfunction-title">. Disabling validation avoids side
effects of the validation process and avoids false positives due
to problems such as forward references. Set this parameter
to <literal>off</> before loading functions on behalf of other
users; <application>pg_dump</> does so automatically.
</para>
</listitem>
</varlistentry>