Skip to content

Backport to 2.27.x: #9801: Fix information leak in policy_reorder_remove - #9854

Merged
timescale-automation merged 1 commit into
2.27.xfrom
backport/2.27.x/9801
May 19, 2026
Merged

Backport to 2.27.x: #9801: Fix information leak in policy_reorder_remove#9854
timescale-automation merged 1 commit into
2.27.xfrom
backport/2.27.x/9801

Conversation

@timescale-automation

Copy link
Copy Markdown
Member

This is an automated backport of #9801: Fix information leak in policy_reorder_remove.
This PR will be merged automatically after all the relevant CI checks pass. If this fix should not be backported, or will be backported manually, just close this PR. You can use the backport branch to add your changes, it won't be modified automatically anymore.

For more details, please see the documentation

Original description

Fix information leak in policy_reorder_remove

Check user permissions before searching for the reorder policy so
callers without rights on the hypertable cannot tell whether a policy
exists or learn the hypertable name from the resulting error or notice.

Check user permissions before searching for the reorder policy so
callers without rights on the hypertable cannot tell whether a policy
exists or learn the hypertable name from the resulting error or notice.

(cherry picked from commit 23a6f53)
@codecov

codecov Bot commented May 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@timescale-automation
timescale-automation merged commit 94039e3 into 2.27.x May 19, 2026
54 checks passed
@timescale-automation
timescale-automation deleted the backport/2.27.x/9801 branch May 19, 2026 06:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

is-auto-backport PR created by backport automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants