Subject Re: [Firebird-Architect] Create of RDB$USERS
Author Dmitry Yemanov
"Alex Peshkov" <pes@...> wrote:
>
> Well, let's leave them 128.

Agreed.

> Related question - there is a real security bug, which comes from
> UserName length. In order to create security class from user name,
> "SQL$" prefix is added to it.

Hmmm. Security classes control access to metadata objects. Every protected
metadata object has a reference to RDB$SECURITY_CLASSES. So you words are
true for table names, etc. But I've never seen a security class defined for
a SQL user. How can it happen? For me, it looks impossible.


Dmitry