1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215
|
#======================================================================
#
# Trigger Tests
# test cases for TRIGGER privilege on db, table and column level
#======================================================================
--disable_abort_on_error
#########################################################
################ Section 3.5.3 ##########################
# Check for mix of user and db level of Triggers #
#########################################################
# General setup to be used in all testcases
let $message= #### Testcase for mix of user(global) and db level: ####;
--source include/show_msg.inc
--disable_warnings
drop database if exists priv_db;
drop database if exists no_priv_db;
--enable_warnings
create database priv_db;
create database no_priv_db;
use priv_db;
eval create table t1 (f1 char(20)) engine= $engine_type;
use no_priv_db;
eval create table t1 (f1 char(20)) engine= $engine_type;
create User test_yesprivs@localhost;
set password for test_yesprivs@localhost = password('PWD');
revoke ALL PRIVILEGES, GRANT OPTION FROM test_yesprivs@localhost;
grant ALL on *.* to test_yesprivs@localhost;
show grants for test_yesprivs@localhost;
create User test_noprivs@localhost;
set password for test_noprivs@localhost = password('PWD');
revoke ALL PRIVILEGES, GRANT OPTION FROM test_noprivs@localhost;
grant SELECT,INSERT on *.* to test_noprivs@localhost;
show grants for test_noprivs@localhost;
connect (yes_privs,localhost,test_yesprivs,PWD,test,$MASTER_MYPORT,$MASTER_MYSOCK);
connect (no_privs,localhost,test_noprivs,PWD,test,$MASTER_MYPORT,$MASTER_MYSOCK);
connection yes_privs;
select current_user;
let $message= trigger privilege on user level for create:;
--source include/show_msg.inc
use priv_db;
create trigger trg1_1 before INSERT on t1 for each row
set new.f1 = 'trig 1_1-yes';
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
use no_priv_db;
create trigger priv_db.trg1_5 before UPDATE on priv_db.t1
for each row
set new.f1 = 'trig 1_5-yes';
insert into priv_db.t1 (f1) values ('insert-no');
select f1 from priv_db.t1 order by f1;
drop trigger priv_db.trg1_5;
connection no_privs;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
connection default;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
revoke TRIGGER on *.* from test_yesprivs@localhost;
show grants for test_yesprivs@localhost;
# change of privilege only active after reconnecting the session
--disable_warnings
disconnect yes_privs;
--enable_warnings
connect (yes_privs,localhost,test_yesprivs,PWD,test,$MASTER_MYPORT,$MASTER_MYSOCK);
select current_user;
use priv_db;
show triggers;
select * from information_schema.triggers;
--error ER_TABLEACCESS_DENIED_ERROR
drop trigger trg1_1;
connection default;
select current_user;
show grants;
drop trigger trg1_1;
use priv_db;
################ Section 3.5.3 ############
# Check for the db level of Triggers #
###########################################
let $message= no trigger privilege on db level for create:;
--source include/show_msg.inc
connection yes_privs;
select current_user;
--error ER_TABLEACCESS_DENIED_ERROR
create trigger trg1_1 before INSERT on t1 for each row
set new.f1 = 'trig 1_1-no';
connection no_privs;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-yes');
select f1 from t1 order by f1;
connection default;
select current_user;
grant TRIGGER on priv_db.* to test_yesprivs@localhost;
show grants for test_yesprivs@localhost;
let $message= trigger privilege on db level for create:;
--source include/show_msg.inc
connection yes_privs;
select current_user;
# active after 'use db'
use priv_db;
create trigger trg1_2 before INSERT on t1 for each row
set new.f1 = 'trig 1_2-yes';
--error ER_TABLEACCESS_DENIED_ERROR
create trigger no_priv_db.trg1_9 before insert on no_priv_db.t1
for each row
set new.f1 = 'trig 1_9-yes';
use no_priv_db;
--error ER_TABLEACCESS_DENIED_ERROR
create trigger trg1_2 before INSERT on t1 for each row
set new.f1 = 'trig 1_2-no';
create trigger priv_db.trg1_9 before UPDATE on priv_db.t1
for each row
set new.f1 = 'trig 1_9-yes';
connection no_privs;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-yes');
select f1 from t1 order by f1;
use no_priv_db;
insert into t1 (f1) values ('insert-yes');
select f1 from t1 order by f1;
--error ER_TABLEACCESS_DENIED_ERROR
drop trigger priv_db.trg1_9;
connection default;
select current_user;
drop trigger priv_db.trg1_9;
revoke TRIGGER on priv_db.* from test_yesprivs@localhost;
use priv_db;
--error ER_TABLEACCESS_DENIED_ERROR
insert into t1 (f1) values ('insert-yes');
select f1 from t1 order by f1;
grant TRIGGER on *.* to test_yesprivs@localhost;
show grants for test_yesprivs@localhost;
connection yes_privs;
select current_user;
use no_priv_db;
--error ER_TABLEACCESS_DENIED_ERROR
create trigger trg1_2 before INSERT on t1 for each row
set new.f1 = 'trig 1_2-no';
connection no_privs;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
use no_priv_db;
insert into t1 (f1) values ('insert-yes');
select f1 from t1 order by f1;
--disable_warnings
disconnect yes_privs;
--enable_warnings
connect (yes_privs,localhost,test_yesprivs,PWD,test,$MASTER_MYPORT,$MASTER_MYSOCK);
select current_user;
use no_priv_db;
create trigger trg1_2 before INSERT on t1 for each row
set new.f1 = 'trig 1_2-yes';
--disable_warnings
disconnect yes_privs;
--enable_warnings
connection no_privs;
select current_user;
use priv_db;
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
use no_priv_db;
insert into t1 (f1) values ('insert-no');
select f1 from t1 order by f1;
--disable_warnings
disconnect no_privs;
# Cleanup table level
connection default;
select current_user;
# general Cleanup
drop database if exists priv_db;
drop database if exists no_priv_db;
drop database if exists h1;
drop user test_yesprivs@localhost;
drop user test_noprivs@localhost;
--enable_warnings
|