2013-10-18 05:45:25 +02:00
|
|
|
|
|
|
|
#create a user with no privileges
|
|
|
|
create user 'test_user'@'localhost';
|
|
|
|
create user 'test_role1'@'';
|
|
|
|
#manualy create role
|
|
|
|
update mysql.user set is_role='Y' where user='test_role1';
|
|
|
|
insert into mysql.roles_mapping (HostFk, UserFk, RoleFk) values ('localhost',
|
|
|
|
'test_user',
|
|
|
|
'test_role1');
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:51:10 +02:00
|
|
|
select user, host from mysql.user where user not like 'root';
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:45:25 +02:00
|
|
|
select * from mysql.roles_mapping;
|
|
|
|
grant select on *.* to 'test_role1'@'';
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:45:25 +02:00
|
|
|
select * from mysql.user where user='test_role1';
|
|
|
|
flush privileges;
|
|
|
|
|
|
|
|
change_user 'test_user';
|
|
|
|
|
|
|
|
--error ER_TABLEACCESS_DENIED_ERROR
|
|
|
|
select * from mysql.roles_mapping;
|
|
|
|
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:45:39 +02:00
|
|
|
show grants;
|
2013-10-18 15:55:26 +02:00
|
|
|
select current_user(), current_role();
|
2013-10-18 05:45:39 +02:00
|
|
|
set role test_role1;
|
2013-10-18 15:55:26 +02:00
|
|
|
select current_user(), current_role();
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:45:39 +02:00
|
|
|
show grants;
|
2013-10-18 15:17:47 +02:00
|
|
|
--sorted_result
|
2013-10-18 05:45:39 +02:00
|
|
|
select * from mysql.roles_mapping;
|
|
|
|
|
|
|
|
set role none;
|
2013-10-18 15:55:26 +02:00
|
|
|
select current_user(), current_role();
|
2013-10-18 05:45:39 +02:00
|
|
|
--error ER_TABLEACCESS_DENIED_ERROR
|
2013-10-18 05:45:25 +02:00
|
|
|
select * from mysql.roles_mapping;
|
|
|
|
|
|
|
|
change_user 'root';
|
|
|
|
delete from mysql.user where user='test_role1';
|
2013-10-18 05:51:19 +02:00
|
|
|
delete from mysql.roles_mapping where RoleFk='test_role1';
|
2013-10-18 05:45:39 +02:00
|
|
|
flush privileges;
|
2013-10-18 05:51:19 +02:00
|
|
|
drop user 'test_user'@'localhost';
|