mirror of
https://github.com/ClickHouse/ClickHouse.git
synced 2024-11-10 09:32:06 +00:00
Address review comments
This commit is contained in:
parent
631c460c96
commit
022d4308ce
@ -0,0 +1,10 @@
|
|||||||
|
<clickhouse>
|
||||||
|
<users>
|
||||||
|
<default>
|
||||||
|
<password></password>
|
||||||
|
<profile>default</profile>
|
||||||
|
<quota>default</quota>
|
||||||
|
<show_named_collections>1</show_named_collections>
|
||||||
|
</default>
|
||||||
|
</users>
|
||||||
|
</clickhouse>
|
@ -3,7 +3,12 @@ from helpers.cluster import ClickHouseCluster
|
|||||||
from helpers.test_tools import TSV
|
from helpers.test_tools import TSV
|
||||||
|
|
||||||
cluster = ClickHouseCluster(__file__)
|
cluster = ClickHouseCluster(__file__)
|
||||||
instance = cluster.add_instance("instance")
|
instance = cluster.add_instance(
|
||||||
|
"instance",
|
||||||
|
user_configs=[
|
||||||
|
"configs/users.d/users.xml",
|
||||||
|
],
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
@pytest.fixture(scope="module", autouse=True)
|
@pytest.fixture(scope="module", autouse=True)
|
||||||
@ -377,8 +382,6 @@ def test_introspection():
|
|||||||
instance.query("GRANT SELECT ON test.table TO A")
|
instance.query("GRANT SELECT ON test.table TO A")
|
||||||
instance.query("GRANT CREATE ON *.* TO B WITH GRANT OPTION")
|
instance.query("GRANT CREATE ON *.* TO B WITH GRANT OPTION")
|
||||||
|
|
||||||
all_access_except_show_named_collections = "SHOW, SELECT, INSERT, ALTER, CREATE, DROP, TRUNCATE, OPTIMIZE, BACKUP, KILL QUERY, KILL TRANSACTION, MOVE PARTITION BETWEEN SHARDS, CREATE USER, ALTER USER, DROP USER, CREATE ROLE, ALTER ROLE, DROP ROLE, ROLE ADMIN, CREATE ROW POLICY, ALTER ROW POLICY, DROP ROW POLICY, CREATE QUOTA, ALTER QUOTA, DROP QUOTA, CREATE SETTINGS PROFILE, ALTER SETTINGS PROFILE, DROP SETTINGS PROFILE, SHOW ACCESS, SYSTEM, dictGet, INTROSPECTION, SOURCES, CLUSTER"
|
|
||||||
|
|
||||||
assert instance.query("SHOW USERS") == TSV(["A", "B", "default"])
|
assert instance.query("SHOW USERS") == TSV(["A", "B", "default"])
|
||||||
assert instance.query("SHOW CREATE USERS A") == TSV(["CREATE USER A"])
|
assert instance.query("SHOW CREATE USERS A") == TSV(["CREATE USER A"])
|
||||||
assert instance.query("SHOW CREATE USERS B") == TSV(["CREATE USER B"])
|
assert instance.query("SHOW CREATE USERS B") == TSV(["CREATE USER B"])
|
||||||
@ -415,7 +418,7 @@ def test_introspection():
|
|||||||
[
|
[
|
||||||
"GRANT SELECT ON test.table TO A",
|
"GRANT SELECT ON test.table TO A",
|
||||||
"GRANT CREATE ON *.* TO B WITH GRANT OPTION",
|
"GRANT CREATE ON *.* TO B WITH GRANT OPTION",
|
||||||
f"GRANT {all_access_except_show_named_collections} ON *.* TO default WITH GRANT OPTION",
|
"GRANT ALL ON *.* TO default WITH GRANT OPTION",
|
||||||
]
|
]
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -436,7 +439,7 @@ def test_introspection():
|
|||||||
[
|
[
|
||||||
"GRANT SELECT ON test.table TO A",
|
"GRANT SELECT ON test.table TO A",
|
||||||
"GRANT CREATE ON *.* TO B WITH GRANT OPTION",
|
"GRANT CREATE ON *.* TO B WITH GRANT OPTION",
|
||||||
f"GRANT {all_access_except_show_named_collections} ON *.* TO default WITH GRANT OPTION",
|
"GRANT ALL ON *.* TO default WITH GRANT OPTION",
|
||||||
]
|
]
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -451,7 +454,7 @@ def test_introspection():
|
|||||||
expected_access2 = (
|
expected_access2 = (
|
||||||
"GRANT SELECT ON test.table TO A\n"
|
"GRANT SELECT ON test.table TO A\n"
|
||||||
"GRANT CREATE ON *.* TO B WITH GRANT OPTION\n"
|
"GRANT CREATE ON *.* TO B WITH GRANT OPTION\n"
|
||||||
f"GRANT {all_access_except_show_named_collections} ON *.* TO default WITH GRANT OPTION"
|
"GRANT ALL ON *.* TO default WITH GRANT OPTION\n"
|
||||||
)
|
)
|
||||||
assert expected_access1 in instance.query("SHOW ACCESS")
|
assert expected_access1 in instance.query("SHOW ACCESS")
|
||||||
assert expected_access2 in instance.query("SHOW ACCESS")
|
assert expected_access2 in instance.query("SHOW ACCESS")
|
||||||
|
@ -40,7 +40,7 @@ def cluster():
|
|||||||
"configs/config.d/named_collections.xml",
|
"configs/config.d/named_collections.xml",
|
||||||
],
|
],
|
||||||
user_configs=[
|
user_configs=[
|
||||||
"configs/users.d/users_no_default_access2.xml",
|
"configs/users.d/users_no_default_access_with_access_management.xml",
|
||||||
],
|
],
|
||||||
stay_alive=True,
|
stay_alive=True,
|
||||||
)
|
)
|
||||||
|
Loading…
Reference in New Issue
Block a user