Tangentially related, I'd like an opinion on this: >Okay, so it's not the most secure password. But Facebook's database servers are heavily firewalled. Though if you do manage to break in to Facebook's servers, there's the password. What is the point on even having a database password? The application itself needs access to the database, so the application needs to know the password. That means that an attacker who g…
This procedure then can apply additional predicates to the query.
When this procedure belongs to the schema that is not directly accessible to the user, then it would be possible to create a filter such that only logged in user can see the records and only her records.