summaryrefslogtreecommitdiff
path: root/mysql-test/suite/roles/set_default_role_invalid.test
blob: 8e72e316d4b6d80331e77e3980635a1da81f8959 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
source include/not_embedded.inc;

# This test checks the error paths possible during set default role.

# Create a user with no privileges
create user test_user@localhost;

create role test_role;
create role not_granted_role;

grant select on *.* to test_role;
grant test_role to test_user@localhost;

change_user 'test_user';
show grants;
--error ER_TABLEACCESS_DENIED_ERROR
select user, host, default_role from mysql.user;

# A user can not set a default role that does not exist in the database.
--error ER_INVALID_ROLE
set default role invalid_role;

# A user can not set a default role if he can not call set role <role>.
--error ER_INVALID_ROLE
set default role not_granted_role;

set default role test_role;

# Even though a user has the default role set, without reconnecting, we should
# not already have the roles privileges.
--error ER_TABLEACCESS_DENIED_ERROR
select user, host, default_role from mysql.user;

change_user 'root';
select user, host, default_role from mysql.user where user='test_user';

change_user 'test_user';
# This should show that the new test_user has the role's grants enabled.
show grants;
select user, host, default_role from mysql.user where user='test_user';

# If we have a failed set default role attempt, don't change the already set
# default role.
--error ER_INVALID_ROLE
set default role invalid_role;
select user, host, default_role from mysql.user where user='test_user';

change_user 'root';
# Now, even though a default role is still set for test_user, make sure the
# user does not get the rights, if he can not set the role.
revoke test_role from test_user@localhost;

change_user 'test_user';
--error ER_TABLEACCESS_DENIED_ERROR
select user, host, default_role from mysql.user where user='test_user';

change_user 'root';

# Cleanup
drop role test_role;
drop role not_granted_role;
drop user test_user@localhost;