Mitigation Strategies
Prev  A. Security Considerations  Next

There is no one-size-fits-all solution. Even disabling Isok's ability to dynamically alter the current search path and the current role does not address the fundamental issues. Even more so because, to be useful, run_isok_queries() may need an expansive set of permissions to do its job.

One possible strategy is to always supply values in the ISOK_QUERIES.Role ISOK_QUERIES.Search_Path columns. At least that way the context of each query's execution is always known.

Another possible strategy is to install Isok in multiple schemas, each schema dedicated to a different purpose and assigned different permissions, intended to be used by different users.


Prev  Up  Next
Roles  Home  Creating an Audit Trail

Page generated: 2025-06-02T22:25:00-05:00.