mirror of
https://github.com/MariaDB/server.git
synced 2025-01-19 05:22:25 +01:00
34da3be8a8
The problem lies in not checking role privileges as well during SHOW DATABASES command. This problem is also apparent for SHOW CREATE DATABASE command. Other SHOW COMMANDS make use of check_access, which in turn makes use of acl_get for both priv_user and priv_role parts, which allows them to function correctly.
55 lines
1.1 KiB
Text
55 lines
1.1 KiB
Text
source include/not_embedded.inc;
|
|
|
|
drop database if exists db;
|
|
|
|
create role r1;
|
|
create user beep@'%';
|
|
|
|
create database db;
|
|
create table db.t1 (i int);
|
|
create table db.t2 (b int);
|
|
grant select on db.* to r1;
|
|
grant r1 to beep@'%';
|
|
|
|
--connect (con1,localhost,beep,,)
|
|
show databases;
|
|
--error ER_DBACCESS_DENIED_ERROR
|
|
show create database db;
|
|
select table_schema, table_name from information_schema.tables
|
|
where table_schema = 'db';
|
|
|
|
set role r1;
|
|
show databases;
|
|
show create database db;
|
|
select table_schema, table_name from information_schema.tables
|
|
where table_schema = 'db';
|
|
|
|
|
|
connection default;
|
|
create role r2;
|
|
create user beep2@'%';
|
|
|
|
grant update on db.* to r2;
|
|
grant r2 to beep2;
|
|
--connect (con2,localhost,beep2,,)
|
|
show databases;
|
|
--error ER_DBACCESS_DENIED_ERROR
|
|
show create database db;
|
|
select table_schema, table_name from information_schema.tables
|
|
where table_schema = 'db';
|
|
|
|
set role r2;
|
|
show databases;
|
|
|
|
show create database db;
|
|
select table_schema, table_name from information_schema.tables
|
|
where table_schema = 'db';
|
|
|
|
|
|
connection default;
|
|
|
|
drop database db;
|
|
drop role r1;
|
|
drop user beep;
|
|
drop role r2;
|
|
drop user beep2;
|