On Tue, Aug 05, 2008 at 11:16:49AM +0200, Paul McCullagh wrote:
> While parsing on the client is great in terms of moving work from the  
> server, a significant drawback is that you don't have the query text on 
> the server.
>
> So you cannot (easily) write a centralized statement log.

and the obvious solution (passing string with bytecode) is fundamentally
flawed as it would be an excellent attack vector. Put nasty "DROP TABLE"
in bytecode, simple select in text.

hrrm... unless we can go from bytecode to SQL, but then it means you
can't grep the app.

problematic, yeah :)
-- 
Stewart Smith

_______________________________________________
Mailing list: https://launchpad.net/~drizzle-discuss
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~drizzle-discuss
More help   : https://help.launchpad.net/ListHelp

Reply via email to