2021-07-19 23:34:04 +00:00
|
|
|
import pytest
|
2022-02-23 21:41:16 +00:00
|
|
|
import uuid
|
2021-07-19 23:34:04 +00:00
|
|
|
from helpers.cluster import ClickHouseCluster
|
|
|
|
|
|
|
|
cluster = ClickHouseCluster(__file__)
|
2022-03-22 16:39:58 +00:00
|
|
|
instance = cluster.add_instance("instance", stay_alive=True)
|
2021-07-19 23:34:04 +00:00
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture(scope="module", autouse=True)
|
|
|
|
def started_cluster():
|
|
|
|
try:
|
|
|
|
cluster.start()
|
|
|
|
yield cluster
|
|
|
|
|
|
|
|
finally:
|
|
|
|
cluster.shutdown()
|
|
|
|
|
2022-02-23 21:41:16 +00:00
|
|
|
|
|
|
|
def test_access_rights_for_function():
|
2021-07-19 23:34:04 +00:00
|
|
|
create_function_query = "CREATE FUNCTION MySum AS (a, b) -> a + b"
|
|
|
|
|
|
|
|
instance.query("CREATE USER A")
|
|
|
|
instance.query("CREATE USER B")
|
2022-03-22 16:39:58 +00:00
|
|
|
assert (
|
|
|
|
"it's necessary to have grant CREATE FUNCTION ON *.*"
|
|
|
|
in instance.query_and_get_error(create_function_query, user="A")
|
|
|
|
)
|
2021-07-19 23:34:04 +00:00
|
|
|
|
|
|
|
instance.query("GRANT CREATE FUNCTION on *.* TO A")
|
2021-08-23 14:31:58 +00:00
|
|
|
|
2022-03-22 16:39:58 +00:00
|
|
|
instance.query(create_function_query, user="A")
|
2021-07-21 07:29:26 +00:00
|
|
|
assert instance.query("SELECT MySum(1, 2)") == "3\n"
|
2021-07-19 23:34:04 +00:00
|
|
|
|
2022-03-22 16:39:58 +00:00
|
|
|
assert (
|
|
|
|
"it's necessary to have grant DROP FUNCTION ON *.*"
|
|
|
|
in instance.query_and_get_error("DROP FUNCTION MySum", user="B")
|
|
|
|
)
|
2021-07-19 23:34:04 +00:00
|
|
|
|
|
|
|
instance.query("GRANT DROP FUNCTION ON *.* TO B")
|
2022-03-22 16:39:58 +00:00
|
|
|
instance.query("DROP FUNCTION MySum", user="B")
|
|
|
|
assert "Unknown function MySum" in instance.query_and_get_error(
|
|
|
|
"SELECT MySum(1, 2)"
|
|
|
|
)
|
2021-07-19 23:34:04 +00:00
|
|
|
|
2021-07-21 13:04:52 +00:00
|
|
|
instance.query("REVOKE CREATE FUNCTION ON *.* FROM A")
|
2022-03-22 16:39:58 +00:00
|
|
|
assert (
|
|
|
|
"it's necessary to have grant CREATE FUNCTION ON *.*"
|
|
|
|
in instance.query_and_get_error(create_function_query, user="A")
|
|
|
|
)
|
2021-08-23 14:31:58 +00:00
|
|
|
|
|
|
|
instance.query("DROP USER IF EXISTS A")
|
|
|
|
instance.query("DROP USER IF EXISTS B")
|
2022-02-23 21:41:16 +00:00
|
|
|
|
|
|
|
|
|
|
|
def test_ignore_obsolete_grant_on_database():
|
|
|
|
instance.stop_clickhouse()
|
|
|
|
|
|
|
|
user_id = uuid.uuid4()
|
2022-03-22 16:39:58 +00:00
|
|
|
instance.exec_in_container(
|
|
|
|
[
|
|
|
|
"bash",
|
|
|
|
"-c",
|
|
|
|
f"""
|
2022-02-23 21:41:16 +00:00
|
|
|
cat > /var/lib/clickhouse/access/{user_id}.sql << EOF
|
|
|
|
ATTACH USER X;
|
|
|
|
ATTACH GRANT CREATE FUNCTION, SELECT ON mydb.* TO X;
|
2022-03-22 16:39:58 +00:00
|
|
|
EOF""",
|
|
|
|
]
|
|
|
|
)
|
2022-02-23 21:41:16 +00:00
|
|
|
|
2022-03-22 16:39:58 +00:00
|
|
|
instance.exec_in_container(
|
|
|
|
["bash", "-c", "touch /var/lib/clickhouse/access/need_rebuild_lists.mark"]
|
|
|
|
)
|
2022-02-23 21:41:16 +00:00
|
|
|
instance.start_clickhouse()
|
|
|
|
|
|
|
|
assert instance.query("SHOW GRANTS FOR X") == "GRANT SELECT ON mydb.* TO X\n"
|