Details
-
Task
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Fixed
-
None
Description
The SUPER privilege should be split up to multiple admin privileges so that more fine grained tuning of what each user can do could be applied.
The SUPER privilege as such should still remain as an alias for all these smaller privileges
Attachments
Issue Links
- blocks
-
MDEV-20299 "sudo" feature in the server
- Open
- causes
-
MDEV-23610 Slave user can't run "SHOW SLAVE STATUS" anymore after upgrade to 10.5, mysql_upgrade should take of that
- Closed
-
MDEV-24344 BINLOG REPLAY privilege is missing from SHOW PRIVILEGES
- Closed
-
MDEV-24362 Privilege aliases are missing from SHOW PRIVILEGES
- Open
-
MDEV-27611 CLONE - Slave user can't run "SHOW SLAVE STATUS" anymore after upgrade to 10.5, mysql_upgrade should take of that
- Closed
- is blocked by
-
MDEV-21689 Add Sql_cmd for GRANT/REVOKE statements
- Closed
-
MDEV-21702 Add a data type for privileges
- Closed
-
MDEV-21704 Add a new JSON field "version_id" into mysql.global_priv.priv
- Closed
- is duplicated by
-
MDEV-18766 Add REPLICATION_SLAVE_ADMIN privilege so that MaxScale doesn't need SUPER privilege to STOP SLAVE or CHANGE MASTER
- Closed
- relates to
-
MDEV-21706 CLIENT_NO_SCHEMA: `GRANT..ON db.table..` changes the explicit database to the current
- Open
-
MDEV-21960 Bind READ_ONLY ADMIN to @@read_only
- Closed
-
MDEV-21961 Bind CONNECTION ADMIN to a number of global system variables
- Closed
-
MDEV-21963 Bind BINLOG ADMIN to a number of global system variables
- Closed
-
MDEV-21966 Bind REPLICATION SLAVE ADMIN to a number of global system variables
- Closed
-
MDEV-21967 Bind REPLICATION {MASTER|SLAVE} ADMIN to rpl_semi_sync_* variables
- Closed
-
MDEV-21969 Bind REPLICATION SLAVE ADMIN to relay_log_*, sync_master_info, sync_relay_log, sync_relay_log_info
- Closed
-
MDEV-21972 Bind REPLICATION MASTER ADMIN to master_verify_checksum
- Closed
-
MDEV-21973 Bind REPLICATION {MASTER|SLAVE} ADMIN to gtid_* GLOBAL-only system variables
- Closed
-
MDEV-22012 Allow SET TIMESTAMP for users with GRANT BINLOG REPLAY when --secure-timestamp=replication
- Closed
-
MDEV-22030 Don't grant REPLICATION MASTER ADMIN automatically on upgrade from an older JSON user table
- Closed
-
MDEV-22057 REPLICATION MASTER ADMIN is missing in root account after upgrade
- Closed
-
MDEV-22152 REPLICATION MASTER ADMIN privilege not given to former SUPER users upon upgrade
- Closed
-
MDEV-29668 SUPER should not allow actions that have fine-grained dedicated privileges
- Closed
-
MDEV-20577 Require lower privilege than SUPER to set rocksdb_create_checkpoint
- Open
-
MDEV-21956 Add class Sys_var_charptr_fscs
- Closed
-
MDEV-21957 Bind BINLOG ADMIN to @@binlog_format, @@binlog_direct_.., @@sql_log_bin
- Closed
-
MDEV-21971 Bind BINLOG ADMIN to binlog_annotate_row_events and binlog_row_image global and session variables
- Closed
-
MDEV-21975 Add BINLOG REPLAY privilege and bind new privileges to gtid_seq_no, preudo_thread_id, server_id, gtid_domain_id
- Closed
-
MDEV-22026 Document 10.5 privilege changes
- Closed