Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-29596

Separate SUPER and READ ONLY ADMIN privileges

Details

    Description

      Remove READ ONLY ADMIN from the SUPER privilege

      The benefit of this is that one can remove the READ ONLY ADMIN privilege
      from all users and this way ensure that no one can do any changes on
      any non-temporary tables.

      This is good option to use on slaves when one wants to ensure that the
      slave is kept identical to the master.

      Attachments

        Issue Links

          Activity

            monty Michael Widenius created issue -
            monty Michael Widenius made changes -
            Field Original Value New Value
            Fix Version/s 10.11 [ 27614 ]
            monty Michael Widenius made changes -
            Status Open [ 1 ] In Progress [ 3 ]

            Pushed to bb-10.11-MDEV-29596

            monty Michael Widenius added a comment - Pushed to bb-10.11- MDEV-29596
            monty Michael Widenius made changes -
            Status In Progress [ 3 ] In Testing [ 10301 ]
            serg Sergei Golubchik made changes -
            Assignee Michael Widenius [ monty ] Elena Stepanova [ elenst ]
            serg Sergei Golubchik made changes -
            serg Sergei Golubchik made changes -
            Affects Version/s 10.11 [ 27614 ]
            Issue Type Bug [ 1 ] Task [ 3 ]
            elenst Elena Stepanova made changes -
            elenst Elena Stepanova made changes -
            elenst Elena Stepanova made changes -
            elenst Elena Stepanova added a comment - - edited

            I have no objections against pushing it as of bb-10.11-MDEV-29596 07581249 (that is, with the fix for MDEV-29632 in addition to the preview commit) into main 10.11 and releasing with 10.11.1.

            Documentation and help topics will need to be updated to reflect the change in SUPER capabilities, but as explained in MDEV-29641, it is usually done asynchronously with releases, so it cannot be a blocker for the feature.

            Note: In OM=>NS replication, if a user with SUPER privilege is created on the master, it will have READ_ONLY ADMIN privilege, while the replicated user on the replica will not. I don't consider it a bug and the scenario is probably of a low importance, I will leave it to the documentation team to decide whether it should be mentioned anywhere (FYI greenman).

            elenst Elena Stepanova added a comment - - edited I have no objections against pushing it as of bb-10.11-MDEV-29596 07581249 (that is, with the fix for MDEV-29632 in addition to the preview commit) into main 10.11 and releasing with 10.11.1. Documentation and help topics will need to be updated to reflect the change in SUPER capabilities, but as explained in MDEV-29641 , it is usually done asynchronously with releases, so it cannot be a blocker for the feature. Note: In OM=>NS replication, if a user with SUPER privilege is created on the master, it will have READ_ONLY ADMIN privilege, while the replicated user on the replica will not. I don't consider it a bug and the scenario is probably of a low importance, I will leave it to the documentation team to decide whether it should be mentioned anywhere (FYI greenman ).
            elenst Elena Stepanova made changes -
            Assignee Elena Stepanova [ elenst ] Sergei Golubchik [ serg ]
            Status In Testing [ 10301 ] Stalled [ 10000 ]
            monty Michael Widenius made changes -
            Status Stalled [ 10000 ] In Progress [ 3 ]
            monty Michael Widenius made changes -
            Status In Progress [ 3 ] Needs Feedback [ 10501 ]
            monty Michael Widenius made changes -
            Fix Version/s N/A [ 14700 ]
            Fix Version/s 10.11 [ 27614 ]
            Resolution Incomplete [ 4 ]
            Status Needs Feedback [ 10501 ] Closed [ 6 ]
            monty Michael Widenius made changes -
            Resolution Incomplete [ 4 ]
            Status Closed [ 6 ] Stalled [ 10000 ]
            monty Michael Widenius made changes -
            Status Stalled [ 10000 ] In Progress [ 3 ]
            serg Sergei Golubchik made changes -
            Status In Progress [ 3 ] Stalled [ 10000 ]
            serg Sergei Golubchik made changes -
            Fix Version/s 10.11 [ 27614 ]
            Fix Version/s N/A [ 14700 ]
            serg Sergei Golubchik made changes -
            serg Sergei Golubchik made changes -
            Priority Major [ 3 ] Critical [ 2 ]
            serg Sergei Golubchik made changes -
            Fix Version/s 10.11.1 [ 28454 ]
            Fix Version/s 10.11 [ 27614 ]
            Resolution Fixed [ 1 ]
            Status Stalled [ 10000 ] Closed [ 6 ]
            ralf.gebhardt Ralf Gebhardt made changes -
            ralf.gebhardt Ralf Gebhardt made changes -
            Labels Preview_10.11

            People

              serg Sergei Golubchik
              monty Michael Widenius
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.