Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/MariaDB/mysql-test/main/   (MariaDB Server Version 8.1-8.4©)  Datei vom 1.9.2026 mit Größe 2 kB image not shown  

Quelle  deny_role_inherit.result   Sprache: Lisp

 

#
# Test DENY + role inheritance: denies on a role propagate
# through the role graph to users and other roles.
#
CREATE DATABASE testdb;
USE testdb;
CREATE TABLE t1 (id INT, val VARCHAR(50));
INSERT INTO t1 VALUES (1,'a'), (2,'b');
CREATE USER u1@localhost;
CREATE ROLE r_grant, r_deny, r_combined;
#
# Setup: r_grant has SELECT, r_deny has DENY SELECT,
# r_combined inherits both. User u1 gets r_combined.
#
GRANT SELECT ON testdb.t1 TO r_grant;
DENY SELECT ON testdb.t1 TO r_deny;
GRANT r_grant TO r_combined;
GRANT r_deny TO r_combined;
GRANT r_combined TO u1@localhost;
#
# DENY from r_deny should win over GRANT from r_grant
#
connect  con1, localhost, u1,,;
SET ROLE r_combined;
SELECT * FROM testdb.t1;
ERROR 42000: SELECT command denied to user 'u1'@'localhost' for table `testdb`.`t1`
disconnect con1;
connection default;
#
# After revoking the deny, SELECT should work again
#
REVOKE DENY SELECT ON testdb.t1 FROM r_deny;
connect  con1, localhost, u1,,;
SET ROLE r_combined;
SELECT * FROM testdb.t1;
id val
1 a
2 b
disconnect con1;
connection default;
# Cleanup scenario 1
REVOKE SELECT ON testdb.t1 FROM r_grant;
DROP ROLE r_grant, r_deny, r_combined;
DROP USER u1@localhost;
#
# DB-level DENY on a role blocks table-level GRANT
# inherited through a different role in the DAG.
#
CREATE USER u2@localhost;
CREATE ROLE r_db_deny, r_tbl_grant, r_top;
DENY SELECT ON testdb.* TO r_db_deny;
GRANT SELECT ON testdb.t1 TO r_tbl_grant;
GRANT r_db_deny TO r_top;
GRANT r_tbl_grant TO r_top;
GRANT r_top TO u2@localhost;
connect  con2, localhost, u2,,;
SET ROLE r_top;
SELECT * FROM testdb.t1;
ERROR 42000: SELECT command denied to user 'u2'@'localhost' for table `testdb`.`t1`
disconnect con2;
connection default;
# Cleanup scenario 2
DROP ROLE r_db_deny, r_tbl_grant, r_top;
DROP USER u2@localhost;
#
# DENY on a leaf role, grant on a higher role:
# deny should still win (deny always wins over grant).
#
CREATE USER u3@localhost;
CREATE ROLE r_child, r_parent;
GRANT r_child TO r_parent;
GRANT r_parent TO u3@localhost;
GRANT SELECT ON testdb.t1 TO r_parent;
DENY SELECT ON testdb.t1 TO r_child;
connect  con3, localhost, u3,,;
SET ROLE r_parent;
SELECT * FROM testdb.t1;
ERROR 42000: SELECT command denied to user 'u3'@'localhost' for table `testdb`.`t1`
disconnect con3;
connection default;
#
# Reverse: deny on parent, grant on child — deny still wins.
#
REVOKE DENY SELECT ON testdb.t1 FROM r_child;
REVOKE SELECT ON testdb.t1 FROM r_parent;
GRANT SELECT ON testdb.t1 TO r_child;
DENY SELECT ON testdb.t1 TO r_parent;
connect  con3, localhost, u3,,;
SET ROLE r_parent;
SELECT * FROM testdb.t1;
ERROR 42000: SELECT command denied to user 'u3'@'localhost' for table `testdb`.`t1`
disconnect con3;
connection default;
# Cleanup scenario 3
DROP ROLE r_child, r_parent;
DROP USER u3@localhost;
# Final cleanup
DROP TABLE testdb.t1;
DROP DATABASE testdb;

Messung V0.5 in Prozent
C=37 H=100 G=75

¤ Dauer der Verarbeitung: 0.11 Sekunden  (vorverarbeitet am  2026-10-08) ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.