利用 MySQL proxies_priv(模拟角色)实现类似用户组管理
角色(Role)可以用来批量管理用户,同一个角色下的用户,拥有相同的权限。
MySQL5.7.X以后可以模拟角色(Role)的功能,通过mysql.proxies_priv模拟实现
[b]1、配置proxy[/b]
mysql> show variables like "%proxy%"; #查看当前proxy是否开启,下图表示没有开启
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090106_0_28860.png[/img]
mysql> set global check_proxy_users =on; #开启proxy 下图表示已开启
mysql> set global mysql_native_password_proxy_users = on;
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090106_1_11642.png[/img]
mysql> exit
Bye #以上设置参数,对当前会话无效,需要退出后重新登录,或直接设置到my.cnf中去
[b]2、创建用户[/b]
mysql> create user will_dba; #类似组
mysql> create user 'will';
mysql> create user 'tom';
#密码就不设置了,如需设置密码后面加上identified by '123'
[b]3、将will_dba的权限映射(map)到will,tom[/b]
mysql> grant proxy on will_dba to will;
mysql> grant proxy on will_dba to tom;
[b]4、给will_dba(模拟的Role)赋予实际权限[/b]
mysql> grant select on *.* to will_dba;
[b]5、查看 will_dba 的权限[/b]
mysql> show grants for will_dba;
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090107_2_94485.png[/img]
[b]6、查看will,和tom 的权限[/b]
mysql> show grants for will;
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090107_3_66945.png[/img]
mysql> show grants for tom;
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090108_4_95996.png[/img]
[b]7、查看 proxies_priv的权限[/b]
mysql> mysql> select * from mysql.proxies_priv;
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090108_5_62449.png[/img]
[b]8、验证[/b]
使用will和tom用户查看数据库
[root@test-1 ~]# mysql -utom -p
mysql> show databases; #tom用户我们之前没有赋予权限,但这里可以查看
mysql> show tables;
mysql> select * from userG
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090108_6_16468.png[/img]
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090109_7_15878.png[/img]
[img]http://img.1sucai.cn/uploads/article/2018010709/20180107090109_8_27136.png[/img]
mysql.proxies_priv仅仅是对Role的模拟,和Oracle的角色还是有所不同.官方称呼为Role like
MySQL5.6.X模拟Role功能需要安装插件,具体方法请参考:
[url=https://dev.mysql.com/doc/refman/5.6/en/proxy-users.html]https://dev.mysql.com/doc/refman/5.6/en/proxy-users.html[/url]
[url=https://dev.mysql.com/doc/refman/5.6/en/pluggable-authentication.html]https://dev.mysql.com/doc/refman/5.6/en/pluggable-authentication.html[/url]
以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持编程素材网。