2020-04-05 23:03:20 +00:00
|
|
|
import pytest
|
|
|
|
from helpers.cluster import ClickHouseCluster
|
|
|
|
|
|
|
|
cluster = ClickHouseCluster(__file__)
|
2022-03-22 16:39:58 +00:00
|
|
|
ch1 = cluster.add_instance(
|
2023-02-05 21:38:07 +00:00
|
|
|
"ch1",
|
|
|
|
main_configs=["configs/config.d/clusters.xml"],
|
|
|
|
user_configs=[
|
|
|
|
"configs/users.d/users.xml",
|
|
|
|
],
|
|
|
|
with_zookeeper=True,
|
2022-03-22 16:39:58 +00:00
|
|
|
)
|
|
|
|
ch2 = cluster.add_instance(
|
2023-02-05 21:38:07 +00:00
|
|
|
"ch2",
|
|
|
|
main_configs=["configs/config.d/clusters.xml"],
|
|
|
|
user_configs=[
|
|
|
|
"configs/users.d/users.xml",
|
|
|
|
],
|
|
|
|
with_zookeeper=True,
|
2022-03-22 16:39:58 +00:00
|
|
|
)
|
|
|
|
ch3 = cluster.add_instance(
|
2023-02-05 21:38:07 +00:00
|
|
|
"ch3",
|
|
|
|
main_configs=["configs/config.d/clusters.xml"],
|
|
|
|
user_configs=[
|
|
|
|
"configs/users.d/users.xml",
|
|
|
|
],
|
|
|
|
with_zookeeper=True,
|
2022-03-22 16:39:58 +00:00
|
|
|
)
|
2020-04-05 23:03:20 +00:00
|
|
|
|
2020-09-16 04:26:10 +00:00
|
|
|
|
2020-04-05 23:03:20 +00:00
|
|
|
@pytest.fixture(scope="module", autouse=True)
|
|
|
|
def started_cluster():
|
|
|
|
try:
|
|
|
|
cluster.start()
|
|
|
|
yield cluster
|
|
|
|
|
|
|
|
finally:
|
|
|
|
cluster.shutdown()
|
|
|
|
|
|
|
|
|
|
|
|
def test_access_control_on_cluster():
|
2022-03-22 16:39:58 +00:00
|
|
|
ch1.query_with_retry(
|
|
|
|
"CREATE USER IF NOT EXISTS Alex ON CLUSTER 'cluster'", retry_count=5
|
|
|
|
)
|
2020-04-05 23:03:20 +00:00
|
|
|
assert ch1.query("SHOW CREATE USER Alex") == "CREATE USER Alex\n"
|
|
|
|
assert ch2.query("SHOW CREATE USER Alex") == "CREATE USER Alex\n"
|
|
|
|
assert ch3.query("SHOW CREATE USER Alex") == "CREATE USER Alex\n"
|
|
|
|
|
2022-03-22 16:39:58 +00:00
|
|
|
ch2.query_with_retry(
|
|
|
|
"GRANT ON CLUSTER 'cluster' SELECT ON *.* TO Alex", retry_count=3
|
|
|
|
)
|
2020-04-05 23:03:20 +00:00
|
|
|
assert ch1.query("SHOW GRANTS FOR Alex") == "GRANT SELECT ON *.* TO Alex\n"
|
|
|
|
assert ch2.query("SHOW GRANTS FOR Alex") == "GRANT SELECT ON *.* TO Alex\n"
|
|
|
|
assert ch3.query("SHOW GRANTS FOR Alex") == "GRANT SELECT ON *.* TO Alex\n"
|
|
|
|
|
2022-03-22 16:39:58 +00:00
|
|
|
ch3.query_with_retry(
|
|
|
|
"REVOKE ON CLUSTER 'cluster' SELECT ON *.* FROM Alex", retry_count=3
|
|
|
|
)
|
2020-04-05 23:03:20 +00:00
|
|
|
assert ch1.query("SHOW GRANTS FOR Alex") == ""
|
|
|
|
assert ch2.query("SHOW GRANTS FOR Alex") == ""
|
|
|
|
assert ch3.query("SHOW GRANTS FOR Alex") == ""
|
|
|
|
|
2021-02-09 15:37:33 +00:00
|
|
|
ch2.query_with_retry("DROP USER Alex ON CLUSTER 'cluster'", retry_count=3)
|
2020-05-03 03:12:03 +00:00
|
|
|
assert "There is no user `Alex`" in ch1.query_and_get_error("SHOW CREATE USER Alex")
|
|
|
|
assert "There is no user `Alex`" in ch2.query_and_get_error("SHOW CREATE USER Alex")
|
|
|
|
assert "There is no user `Alex`" in ch3.query_and_get_error("SHOW CREATE USER Alex")
|
2022-07-01 10:18:09 +00:00
|
|
|
|
|
|
|
|
|
|
|
def test_grant_all_on_cluster():
|
|
|
|
ch1.query("CREATE USER IF NOT EXISTS Alex ON CLUSTER 'cluster'")
|
|
|
|
ch1.query("GRANT ALL ON *.* TO Alex ON CLUSTER 'cluster'")
|
|
|
|
|
|
|
|
assert ch1.query("SHOW GRANTS FOR Alex") == "GRANT ALL ON *.* TO Alex\n"
|
|
|
|
assert ch2.query("SHOW GRANTS FOR Alex") == "GRANT ALL ON *.* TO Alex\n"
|
|
|
|
|
|
|
|
ch1.query("DROP USER Alex ON CLUSTER 'cluster'")
|