Type:
Bug
Priority:
Major
Resolution:
Fixed
Affects Version/s:
10.3(EOL) , 10.4(EOL) , 10.5 , 10.6 , 10.7(EOL) , 10.8(EOL) , 10.9(EOL) , 10.10(EOL)
There appears to be an inconsistency of when privileges of a role are applied indirectly via another role and when the user connects to the server.
For instance - role1->user, role2->role1; user connects and has role2 privileges:
create role admin;
create role student;
create database crm;
grant create on crm.* to admin;
grant select on crm.* to student;
create user intern@localhost;
grant student to intern@localhost;
set default role student for intern@localhost;
grant admin to student;
connect (con1, localhost, intern,,);
use crm;
create table t1 (a int );
disconnect con1;
# cleanup
connection default ;
drop user intern@localhost;
drop role student;
drop role admin;
drop database crm;
flush privileges ;
However - role1->user; user connects; role2->role1; user connects but does not have role2 privileges. FLUSH PRIVILEGES is needed before user has role2 capabilities:
create role admin;
create role student;
create database crm;
grant create on crm.* to admin;
grant select on crm.* to student;
create user intern@localhost;
grant student to intern@localhost;
set default role student for intern@localhost;
connect (con1, localhost, intern,,);
use crm;
disconnect con1;
connection default ;
grant admin to student;
connect (con1, localhost, intern,,);
use crm;
--error ER_TABLEACCESS_DENIED_ERROR
create table t1 (a int );
disconnect con1;
connection default ;
flush privileges ;
connect (con1, localhost, intern,,);
use crm;
create table t1 (a int );
disconnect con1;
# cleanup
connection default ;
drop user intern@localhost;
drop role student;
drop role admin;
drop database crm;
flush privileges ;
Why this is the case is not clear to me.
relates to
MDEV-5771
Privileges acquired via roles depend on the order of granting
Closed
Angelique Sklavounos (Inactive)
made changes -
2022-10-21 20:33
Field
Original Value
New Value
Fix Version/s
10.3
[ 22126
]
Fix Version/s
10.4
[ 22408
]
Fix Version/s
10.5
[ 23123
]
Fix Version/s
10.6
[ 24028
]
Fix Version/s
10.7
[ 24805
]
Fix Version/s
10.8
[ 26121
]
Fix Version/s
10.9
[ 26905
]
Fix Version/s
10.10
[ 27530
]
Sergei Golubchik
made changes -
2022-10-22 10:18
Assignee
Oleksandr Byelkin
[ sanja
]
Sergei Golubchik
[ serg
]
Sergei Golubchik
made changes -
2022-10-22 10:18
Status
Open
[ 1
]
In Progress
[ 3
]
Sergei Golubchik
made changes -
2022-10-22 15:07
Summary
Role privileges via intermediate role applied inconsistently
Cached role privileges are not invalidated when needed
Sergei Golubchik
made changes -
2022-10-22 17:54
Fix Version/s
10.3.37
[ 28404
]
Fix Version/s
10.4.27
[ 28405
]
Fix Version/s
10.5.18
[ 28421
]
Fix Version/s
10.6.11
[ 28441
]
Fix Version/s
10.7.7
[ 28442
]
Fix Version/s
10.8.6
[ 28443
]
Fix Version/s
10.9.4
[ 28444
]
Fix Version/s
10.3
[ 22126
]
Fix Version/s
10.4
[ 22408
]
Fix Version/s
10.5
[ 23123
]
Fix Version/s
10.6
[ 24028
]
Fix Version/s
10.7
[ 24805
]
Fix Version/s
10.8
[ 26121
]
Fix Version/s
10.9
[ 26905
]
Fix Version/s
10.10
[ 27530
]
Resolution
Fixed
[ 1
]
Status
In Progress
[ 3
]
Closed
[ 6
]
{"report":{"fcp":1951.8000001907349,"ttfb":553.0999999046326,"pageVisibility":"visible","entityId":115881,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"3fb8d9f7-f2b9-46b9-949a-b45d50ed8d80","navigationType":0,"readyForUser":2059.199999809265,"redirectCount":0,"resourceLoadedEnd":2252.9000000953674,"resourceLoadedStart":558.3000001907349,"resourceTiming":[{"duration":884,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":558.3000001907349,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":558.3000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1442.3000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":884,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":558.6999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":558.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1442.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":895,"initiatorType":"script","name":"https://jira.mariadb.org/s/e9b27a47da5fb0f74a35acd57e9847fb-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":558.8000001907349,"connectEnd":558.8000001907349,"connectStart":558.8000001907349,"domainLookupEnd":558.8000001907349,"domainLookupStart":558.8000001907349,"fetchStart":558.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":558.8000001907349,"responseEnd":1453.8000001907349,"responseStart":1453.8000001907349,"secureConnectionStart":558.8000001907349},{"duration":932.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/c32eb0da7ad9831253f8397e6cc26afd-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":559,"connectEnd":559,"connectStart":559,"domainLookupEnd":559,"domainLookupStart":559,"fetchStart":559,"redirectEnd":0,"redirectStart":0,"requestStart":559,"responseEnd":1491.3000001907349,"responseStart":1491.3000001907349,"secureConnectionStart":559},{"duration":936.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/bc0bcb146314416123c992714ee00ff7-CDN/lu2bv2/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":559.1999998092651,"connectEnd":559.1999998092651,"connectStart":559.1999998092651,"domainLookupEnd":559.1999998092651,"domainLookupStart":559.1999998092651,"fetchStart":559.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":559.1999998092651,"responseEnd":1495.9000000953674,"responseStart":1495.9000000953674,"secureConnectionStart":559.1999998092651},{"duration":937.0999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":559.4000000953674,"connectEnd":559.4000000953674,"connectStart":559.4000000953674,"domainLookupEnd":559.4000000953674,"domainLookupStart":559.4000000953674,"fetchStart":559.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":559.4000000953674,"responseEnd":1496.5,"responseStart":1496.5,"secureConnectionStart":559.4000000953674},{"duration":937.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":559.5999999046326,"connectEnd":559.5999999046326,"connectStart":559.5999999046326,"domainLookupEnd":559.5999999046326,"domainLookupStart":559.5999999046326,"fetchStart":559.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":559.5999999046326,"responseEnd":1496.9000000953674,"responseStart":1496.9000000953674,"secureConnectionStart":559.5999999046326},{"duration":1044.1999998092651,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bv2/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":559.8000001907349,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":559.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1604,"responseStart":0,"secureConnectionStart":0},{"duration":937.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":560,"connectEnd":560,"connectStart":560,"domainLookupEnd":560,"domainLookupStart":560,"fetchStart":560,"redirectEnd":0,"redirectStart":0,"requestStart":560,"responseEnd":1497.3000001907349,"responseStart":1497.3000001907349,"secureConnectionStart":560},{"duration":1043.9000000953674,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":560.1999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":560.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1604.0999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":937.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/719848dd97ebe0663199f49a3936487a-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":560.4000000953674,"connectEnd":560.4000000953674,"connectStart":560.4000000953674,"domainLookupEnd":560.4000000953674,"domainLookupStart":560.4000000953674,"fetchStart":560.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":560.4000000953674,"responseEnd":1498.0999999046326,"responseStart":1498.0999999046326,"secureConnectionStart":560.4000000953674},{"duration":1685.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":566.3000001907349,"connectEnd":566.3000001907349,"connectStart":566.3000001907349,"domainLookupEnd":566.3000001907349,"domainLookupStart":566.3000001907349,"fetchStart":566.3000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":566.3000001907349,"responseEnd":2252,"responseStart":2252,"secureConnectionStart":566.3000001907349},{"duration":1676.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":576,"connectEnd":576,"connectStart":576,"domainLookupEnd":576,"domainLookupStart":576,"fetchStart":576,"redirectEnd":0,"redirectStart":0,"requestStart":576,"responseEnd":2252.9000000953674,"responseStart":2252.9000000953674,"secureConnectionStart":576},{"duration":292.40000009536743,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1622,"connectEnd":1622,"connectStart":1622,"domainLookupEnd":1622,"domainLookupStart":1622,"fetchStart":1622,"redirectEnd":0,"redirectStart":0,"requestStart":1622,"responseEnd":1914.4000000953674,"responseStart":1914.4000000953674,"secureConnectionStart":1622},{"duration":431.5,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1944.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1944.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":2376,"responseStart":0,"secureConnectionStart":0},{"duration":407.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bv2/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1968.0999999046326,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1968.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":2375.699999809265,"responseStart":0,"secureConnectionStart":0},{"duration":384.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1969.0999999046326,"connectEnd":1969.0999999046326,"connectStart":1969.0999999046326,"domainLookupEnd":1969.0999999046326,"domainLookupStart":1969.0999999046326,"fetchStart":1969.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":1969.0999999046326,"responseEnd":2353.5,"responseStart":2353.5,"secureConnectionStart":1969.0999999046326}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":341,"responseStart":553,"responseEnd":575,"domLoading":556,"domInteractive":2283,"domContentLoadedEventStart":2283,"domContentLoadedEventEnd":2333,"domComplete":2638,"loadEventStart":2638,"loadEventEnd":2638,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":2259.4000000953674},{"name":"bigPipe.sidebar-id.end","time":2260.300000190735},{"name":"bigPipe.activity-panel-pipe-id.start","time":2260.5},{"name":"bigPipe.activity-panel-pipe-id.end","time":2263.800000190735},{"name":"activityTabFullyLoaded","time":2388.5}],"measures":[],"correlationId":"fe9fc01ce972dd","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":129,"dbReadsTimeInMs":17,"dbConnsTimeInMs":24,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}