mndUser.c 23.4 KB
Newer Older
H
refact  
Hongze Cheng 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * Copyright (c) 2019 TAOS Data, Inc. <jhtao@taosdata.com>
 *
 * This program is free software: you can use, redistribute, and/or modify
 * it under the terms of the GNU Affero General Public License, version 3
 * or later ("AGPL"), as published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.
 *
 * You should have received a copy of the GNU Affero General Public License
 * along with this program. If not, see <http://www.gnu.org/licenses/>.
 */

S
Shengliang Guan 已提交
16
#define _DEFAULT_SOURCE
S
Shengliang Guan 已提交
17
#include "mndUser.h"
S
Shengliang Guan 已提交
18
#include "mndAuth.h"
S
Shengliang Guan 已提交
19
#include "mndDb.h"
S
Shengliang Guan 已提交
20
#include "mndShow.h"
S
Shengliang Guan 已提交
21
#include "mndTrans.h"
S
tbase64  
Shengliang Guan 已提交
22
#include "tbase64.h"
S
Shengliang Guan 已提交
23

24 25
#define USER_VER_NUMBER   1
#define USER_RESERVE_SIZE 64
S
Shengliang Guan 已提交
26

S
Shengliang Guan 已提交
27 28 29 30
static int32_t  mndCreateDefaultUsers(SMnode *pMnode);
static SSdbRow *mndUserActionDecode(SSdbRaw *pRaw);
static int32_t  mndUserActionInsert(SSdb *pSdb, SUserObj *pUser);
static int32_t  mndUserActionDelete(SSdb *pSdb, SUserObj *pUser);
S
Shengliang Guan 已提交
31
static int32_t  mndUserActionUpdate(SSdb *pSdb, SUserObj *pOld, SUserObj *pNew);
S
Shengliang Guan 已提交
32 33 34 35 36
static int32_t  mndCreateUser(SMnode *pMnode, char *acct, SCreateUserReq *pCreate, SNodeMsg *pReq);
static int32_t  mndProcessCreateUserReq(SNodeMsg *pReq);
static int32_t  mndProcessAlterUserReq(SNodeMsg *pReq);
static int32_t  mndProcessDropUserReq(SNodeMsg *pReq);
static int32_t  mndProcessGetUserAuthReq(SNodeMsg *pReq);
37
static int32_t  mndRetrieveUsers(SNodeMsg *pReq, SShowObj *pShow, SSDataBlock *pBlock, int32_t rows);
S
Shengliang Guan 已提交
38
static void     mndCancelGetNextUser(SMnode *pMnode, void *pIter);
S
Shengliang Guan 已提交
39 40

int32_t mndInitUser(SMnode *pMnode) {
S
Shengliang Guan 已提交
41 42 43 44 45 46 47 48 49 50
  SSdbTable table = {
      .sdbType = SDB_USER,
      .keyType = SDB_KEY_BINARY,
      .deployFp = (SdbDeployFp)mndCreateDefaultUsers,
      .encodeFp = (SdbEncodeFp)mndUserActionEncode,
      .decodeFp = (SdbDecodeFp)mndUserActionDecode,
      .insertFp = (SdbInsertFp)mndUserActionInsert,
      .updateFp = (SdbUpdateFp)mndUserActionUpdate,
      .deleteFp = (SdbDeleteFp)mndUserActionDelete,
  };
S
Shengliang Guan 已提交
51

S
Shengliang Guan 已提交
52 53 54
  mndSetMsgHandle(pMnode, TDMT_MND_CREATE_USER, mndProcessCreateUserReq);
  mndSetMsgHandle(pMnode, TDMT_MND_ALTER_USER, mndProcessAlterUserReq);
  mndSetMsgHandle(pMnode, TDMT_MND_DROP_USER, mndProcessDropUserReq);
S
Shengliang Guan 已提交
55
  mndSetMsgHandle(pMnode, TDMT_MND_GET_USER_AUTH, mndProcessGetUserAuthReq);
S
Shengliang Guan 已提交
56

S
Shengliang Guan 已提交
57 58
  mndAddShowRetrieveHandle(pMnode, TSDB_MGMT_TABLE_USER, mndRetrieveUsers);
  mndAddShowFreeIterHandle(pMnode, TSDB_MGMT_TABLE_USER, mndCancelGetNextUser);
S
Shengliang Guan 已提交
59 60 61 62 63 64 65
  return sdbSetTable(pMnode->pSdb, table);
}

void mndCleanupUser(SMnode *pMnode) {}

static int32_t mndCreateDefaultUser(SMnode *pMnode, char *acct, char *user, char *pass) {
  SUserObj userObj = {0};
S
Shengliang Guan 已提交
66
  taosEncryptPass_c((uint8_t *)pass, strlen(pass), userObj.pass);
S
Shengliang Guan 已提交
67 68 69 70 71 72
  tstrncpy(userObj.user, user, TSDB_USER_LEN);
  tstrncpy(userObj.acct, acct, TSDB_USER_LEN);
  userObj.createdTime = taosGetTimestampMs();
  userObj.updateTime = userObj.createdTime;

  if (strcmp(user, TSDB_DEFAULT_USER) == 0) {
73
    userObj.superUser = 1;
S
Shengliang Guan 已提交
74 75 76 77 78 79
  }

  SSdbRaw *pRaw = mndUserActionEncode(&userObj);
  if (pRaw == NULL) return -1;
  sdbSetRawStatus(pRaw, SDB_STATUS_READY);

S
Shengliang Guan 已提交
80
  mDebug("user:%s, will be created while deploy sdb, raw:%p", userObj.user, pRaw);
S
Shengliang Guan 已提交
81 82 83 84 85 86 87 88 89 90 91
  return sdbWrite(pMnode->pSdb, pRaw);
}

static int32_t mndCreateDefaultUsers(SMnode *pMnode) {
  if (mndCreateDefaultUser(pMnode, TSDB_DEFAULT_USER, TSDB_DEFAULT_USER, TSDB_DEFAULT_PASS) != 0) {
    return -1;
  }

  return 0;
}

92
SSdbRaw *mndUserActionEncode(SUserObj *pUser) {
93 94
  terrno = TSDB_CODE_OUT_OF_MEMORY;

S
Shengliang Guan 已提交
95 96
  int32_t numOfReadDbs = taosHashGetSize(pUser->readDbs);
  int32_t numOfWriteDbs = taosHashGetSize(pUser->writeDbs);
97
  int32_t size = sizeof(SUserObj) + USER_RESERVE_SIZE + (numOfReadDbs + numOfWriteDbs) * TSDB_DB_FNAME_LEN;
S
Shengliang Guan 已提交
98

99
  SSdbRaw *pRaw = sdbAllocRaw(SDB_USER, USER_VER_NUMBER, size);
100
  if (pRaw == NULL) goto _OVER;
S
Shengliang Guan 已提交
101 102

  int32_t dataPos = 0;
103 104 105 106 107 108
  SDB_SET_BINARY(pRaw, dataPos, pUser->user, TSDB_USER_LEN, _OVER)
  SDB_SET_BINARY(pRaw, dataPos, pUser->pass, TSDB_PASSWORD_LEN, _OVER)
  SDB_SET_BINARY(pRaw, dataPos, pUser->acct, TSDB_USER_LEN, _OVER)
  SDB_SET_INT64(pRaw, dataPos, pUser->createdTime, _OVER)
  SDB_SET_INT64(pRaw, dataPos, pUser->updateTime, _OVER)
  SDB_SET_INT8(pRaw, dataPos, pUser->superUser, _OVER)
109
  SDB_SET_INT32(pRaw, dataPos, pUser->authVersion, _OVER)
110 111
  SDB_SET_INT32(pRaw, dataPos, numOfReadDbs, _OVER)
  SDB_SET_INT32(pRaw, dataPos, numOfWriteDbs, _OVER)
112 113 114

  char *db = taosHashIterate(pUser->readDbs, NULL);
  while (db != NULL) {
115
    SDB_SET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER);
116 117 118 119 120
    db = taosHashIterate(pUser->readDbs, db);
  }

  db = taosHashIterate(pUser->writeDbs, NULL);
  while (db != NULL) {
121
    SDB_SET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER);
122 123 124
    db = taosHashIterate(pUser->writeDbs, db);
  }

125 126
  SDB_SET_RESERVE(pRaw, dataPos, USER_RESERVE_SIZE, _OVER)
  SDB_SET_DATALEN(pRaw, dataPos, _OVER)
127 128 129

  terrno = 0;

130
_OVER:
131 132 133 134 135
  if (terrno != 0) {
    mError("user:%s, failed to encode to raw:%p since %s", pUser->user, pRaw, terrstr());
    sdbFreeRaw(pRaw);
    return NULL;
  }
S
Shengliang Guan 已提交
136

S
Shengliang Guan 已提交
137
  mTrace("user:%s, encode to raw:%p, row:%p", pUser->user, pRaw, pUser);
S
Shengliang Guan 已提交
138
  return pRaw;
S
Shengliang Guan 已提交
139 140
}

S
Shengliang Guan 已提交
141
static SSdbRow *mndUserActionDecode(SSdbRaw *pRaw) {
142 143
  terrno = TSDB_CODE_OUT_OF_MEMORY;

S
Shengliang Guan 已提交
144
  int8_t sver = 0;
145
  if (sdbGetRawSoftVer(pRaw, &sver) != 0) goto _OVER;
S
Shengliang Guan 已提交
146

147
  if (sver != USER_VER_NUMBER) {
S
Shengliang Guan 已提交
148
    terrno = TSDB_CODE_SDB_INVALID_DATA_VER;
149
    goto _OVER;
S
Shengliang Guan 已提交
150
  }
S
Shengliang Guan 已提交
151

152
  SSdbRow *pRow = sdbAllocRow(sizeof(SUserObj));
153
  if (pRow == NULL) goto _OVER;
154

S
Shengliang Guan 已提交
155
  SUserObj *pUser = sdbGetRowObj(pRow);
156
  if (pUser == NULL) goto _OVER;
157

S
Shengliang Guan 已提交
158
  int32_t dataPos = 0;
159 160 161 162 163 164
  SDB_GET_BINARY(pRaw, dataPos, pUser->user, TSDB_USER_LEN, _OVER)
  SDB_GET_BINARY(pRaw, dataPos, pUser->pass, TSDB_PASSWORD_LEN, _OVER)
  SDB_GET_BINARY(pRaw, dataPos, pUser->acct, TSDB_USER_LEN, _OVER)
  SDB_GET_INT64(pRaw, dataPos, &pUser->createdTime, _OVER)
  SDB_GET_INT64(pRaw, dataPos, &pUser->updateTime, _OVER)
  SDB_GET_INT8(pRaw, dataPos, &pUser->superUser, _OVER)
165
  SDB_GET_INT32(pRaw, dataPos, &pUser->authVersion, _OVER)
166 167 168

  int32_t numOfReadDbs = 0;
  int32_t numOfWriteDbs = 0;
169 170
  SDB_GET_INT32(pRaw, dataPos, &numOfReadDbs, _OVER)
  SDB_GET_INT32(pRaw, dataPos, &numOfWriteDbs, _OVER)
S
Shengliang Guan 已提交
171 172 173
  pUser->readDbs = taosHashInit(numOfReadDbs, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
  pUser->writeDbs =
      taosHashInit(numOfWriteDbs, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
174
  if (pUser->readDbs == NULL || pUser->writeDbs == NULL) goto _OVER;
175 176 177

  for (int32_t i = 0; i < numOfReadDbs; ++i) {
    char db[TSDB_DB_FNAME_LEN] = {0};
178
    SDB_GET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER)
179 180 181 182 183 184
    int32_t len = strlen(db) + 1;
    taosHashPut(pUser->readDbs, db, len, db, TSDB_DB_FNAME_LEN);
  }

  for (int32_t i = 0; i < numOfWriteDbs; ++i) {
    char db[TSDB_DB_FNAME_LEN] = {0};
185
    SDB_GET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER)
186 187 188 189
    int32_t len = strlen(db) + 1;
    taosHashPut(pUser->writeDbs, db, len, db, TSDB_DB_FNAME_LEN);
  }

190
  SDB_GET_RESERVE(pRaw, dataPos, USER_RESERVE_SIZE, _OVER)
S
Shengliang Guan 已提交
191
  taosInitRWLatch(&pUser->lock);
192 193 194

  terrno = 0;

195
_OVER:
196 197
  if (terrno != 0) {
    mError("user:%s, failed to decode from raw:%p since %s", pUser->user, pRaw, terrstr());
198 199
    taosHashCleanup(pUser->readDbs);
    taosHashCleanup(pUser->writeDbs);
wafwerar's avatar
wafwerar 已提交
200
    taosMemoryFreeClear(pRow);
201 202
    return NULL;
  }
S
Shengliang Guan 已提交
203

S
Shengliang Guan 已提交
204
  mTrace("user:%s, decode from raw:%p, row:%p", pUser->user, pRaw, pUser);
S
Shengliang Guan 已提交
205
  return pRow;
S
Shengliang Guan 已提交
206
}
S
Shengliang Guan 已提交
207

S
Shengliang Guan 已提交
208
static int32_t mndUserActionInsert(SSdb *pSdb, SUserObj *pUser) {
S
Shengliang Guan 已提交
209
  mTrace("user:%s, perform insert action, row:%p", pUser->user, pUser);
S
Shengliang Guan 已提交
210

S
Shengliang Guan 已提交
211 212
  SAcctObj *pAcct = sdbAcquire(pSdb, SDB_ACCT, pUser->acct);
  if (pAcct == NULL) {
S
Shengliang Guan 已提交
213
    terrno = TSDB_CODE_MND_ACCT_NOT_EXIST;
S
Shengliang Guan 已提交
214
    mError("user:%s, failed to perform insert action since %s", pUser->user, terrstr());
S
Shengliang Guan 已提交
215
    return -1;
S
Shengliang Guan 已提交
216
  }
S
Shengliang Guan 已提交
217 218
  pUser->acctId = pAcct->acctId;
  sdbRelease(pSdb, pAcct);
S
Shengliang Guan 已提交
219

S
Shengliang Guan 已提交
220 221
  return 0;
}
S
Shengliang Guan 已提交
222

S
Shengliang Guan 已提交
223
static int32_t mndUserActionDelete(SSdb *pSdb, SUserObj *pUser) {
S
Shengliang Guan 已提交
224
  mTrace("user:%s, perform delete action, row:%p", pUser->user, pUser);
225 226
  taosHashCleanup(pUser->readDbs);
  taosHashCleanup(pUser->writeDbs);
227 228
  pUser->readDbs = NULL;
  pUser->writeDbs = NULL;
S
Shengliang Guan 已提交
229 230 231
  return 0;
}

S
Shengliang Guan 已提交
232
static int32_t mndUserActionUpdate(SSdb *pSdb, SUserObj *pOld, SUserObj *pNew) {
S
Shengliang Guan 已提交
233
  mTrace("user:%s, perform update action, old row:%p new row:%p", pOld->user, pOld, pNew);
S
Shengliang Guan 已提交
234
  taosWLockLatch(&pOld->lock);
S
Shengliang Guan 已提交
235
  pOld->updateTime = pNew->updateTime;
S
Shengliang Guan 已提交
236
  memcpy(pOld->pass, pNew->pass, TSDB_PASSWORD_LEN);
wafwerar's avatar
wafwerar 已提交
237 238
  TSWAP(pOld->readDbs, pNew->readDbs);
  TSWAP(pOld->writeDbs, pNew->writeDbs);
S
Shengliang Guan 已提交
239
  taosWUnLockLatch(&pOld->lock);
240

S
Shengliang Guan 已提交
241 242 243
  return 0;
}

244
SUserObj *mndAcquireUser(SMnode *pMnode, const char *userName) {
S
Shengliang Guan 已提交
245 246 247
  SSdb     *pSdb = pMnode->pSdb;
  SUserObj *pUser = sdbAcquire(pSdb, SDB_USER, userName);
  if (pUser == NULL) {
S
Shengliang Guan 已提交
248
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
S
Shengliang Guan 已提交
249 250
  }
  return pUser;
S
Shengliang Guan 已提交
251
}
S
Shengliang Guan 已提交
252

S
Shengliang Guan 已提交
253 254 255
void mndReleaseUser(SMnode *pMnode, SUserObj *pUser) {
  SSdb *pSdb = pMnode->pSdb;
  sdbRelease(pSdb, pUser);
S
Shengliang Guan 已提交
256 257
}

S
Shengliang Guan 已提交
258
static int32_t mndCreateUser(SMnode *pMnode, char *acct, SCreateUserReq *pCreate, SNodeMsg *pReq) {
S
Shengliang Guan 已提交
259
  SUserObj userObj = {0};
S
Shengliang Guan 已提交
260 261
  taosEncryptPass_c((uint8_t *)pCreate->pass, strlen(pCreate->pass), userObj.pass);
  tstrncpy(userObj.user, pCreate->user, TSDB_USER_LEN);
S
Shengliang Guan 已提交
262 263 264
  tstrncpy(userObj.acct, acct, TSDB_USER_LEN);
  userObj.createdTime = taosGetTimestampMs();
  userObj.updateTime = userObj.createdTime;
S
Shengliang Guan 已提交
265
  userObj.superUser = pCreate->superUser;
S
Shengliang Guan 已提交
266

S
Shengliang Guan 已提交
267
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_CREATE_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
268
  if (pTrans == NULL) {
S
Shengliang Guan 已提交
269
    mError("user:%s, failed to create since %s", pCreate->user, terrstr());
S
Shengliang Guan 已提交
270 271
    return -1;
  }
S
Shengliang Guan 已提交
272
  mDebug("trans:%d, used to create user:%s", pTrans->id, pCreate->user);
S
Shengliang Guan 已提交
273

S
Shengliang Guan 已提交
274
  SSdbRaw *pRedoRaw = mndUserActionEncode(&userObj);
S
Shengliang Guan 已提交
275
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
S
Shengliang Guan 已提交
276
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
S
Shengliang Guan 已提交
277
    mndTransDrop(pTrans);
S
Shengliang Guan 已提交
278
    return -1;
S
Shengliang Guan 已提交
279
  }
S
Shengliang Guan 已提交
280 281
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_READY);

S
Shengliang Guan 已提交
282
  if (mndTransPrepare(pMnode, pTrans) != 0) {
S
Shengliang Guan 已提交
283
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
S
Shengliang Guan 已提交
284
    mndTransDrop(pTrans);
S
Shengliang Guan 已提交
285
    return -1;
S
Shengliang Guan 已提交
286 287
  }

S
Shengliang Guan 已提交
288
  mndTransDrop(pTrans);
S
Shengliang Guan 已提交
289
  return 0;
S
Shengliang Guan 已提交
290 291
}

S
Shengliang Guan 已提交
292 293
static int32_t mndProcessCreateUserReq(SNodeMsg *pReq) {
  SMnode        *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
294 295 296 297 298
  int32_t        code = -1;
  SUserObj      *pUser = NULL;
  SUserObj      *pOperUser = NULL;
  SCreateUserReq createReq = {0};

S
Shengliang Guan 已提交
299 300
  if (tDeserializeSCreateUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &createReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
301
    goto _OVER;
S
Shengliang Guan 已提交
302
  }
S
Shengliang Guan 已提交
303

S
Shengliang Guan 已提交
304
  mDebug("user:%s, start to create", createReq.user);
S
Shengliang Guan 已提交
305

S
Shengliang Guan 已提交
306
  if (createReq.user[0] == 0) {
S
Shengliang Guan 已提交
307
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
308
    goto _OVER;
S
Shengliang Guan 已提交
309 310
  }

S
Shengliang Guan 已提交
311
  if (createReq.pass[0] == 0) {
S
Shengliang Guan 已提交
312
    terrno = TSDB_CODE_MND_INVALID_PASS_FORMAT;
313
    goto _OVER;
S
Shengliang Guan 已提交
314 315
  }

S
Shengliang Guan 已提交
316
  pUser = mndAcquireUser(pMnode, createReq.user);
S
Shengliang Guan 已提交
317
  if (pUser != NULL) {
S
Shengliang Guan 已提交
318
    terrno = TSDB_CODE_MND_USER_ALREADY_EXIST;
319
    goto _OVER;
S
Shengliang Guan 已提交
320 321
  }

S
Shengliang Guan 已提交
322
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
323
  if (pOperUser == NULL) {
S
Shengliang Guan 已提交
324
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
325
    goto _OVER;
S
Shengliang Guan 已提交
326 327
  }

S
Shengliang Guan 已提交
328
  if (mndCheckCreateUserAuth(pOperUser) != 0) {
329
    goto _OVER;
S
Shengliang Guan 已提交
330 331 332
  }

  code = mndCreateUser(pMnode, pOperUser->acct, &createReq, pReq);
S
Shengliang Guan 已提交
333
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
334

335
_OVER:
S
Shengliang Guan 已提交
336 337
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to create since %s", createReq.user, terrstr());
S
Shengliang Guan 已提交
338 339
  }

S
Shengliang Guan 已提交
340 341 342 343
  mndReleaseUser(pMnode, pUser);
  mndReleaseUser(pMnode, pOperUser);

  return code;
S
Shengliang Guan 已提交
344 345
}

S
Shengliang Guan 已提交
346
static int32_t mndAlterUser(SMnode *pMnode, SUserObj *pOld, SUserObj *pNew, SNodeMsg *pReq) {
S
Shengliang Guan 已提交
347
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_ALTER_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
348
  if (pTrans == NULL) {
S
Shengliang Guan 已提交
349
    mError("user:%s, failed to alter since %s", pOld->user, terrstr());
S
Shengliang Guan 已提交
350 351
    return -1;
  }
S
Shengliang Guan 已提交
352
  mDebug("trans:%d, used to alter user:%s", pTrans->id, pOld->user);
S
Shengliang Guan 已提交
353

S
Shengliang Guan 已提交
354
  SSdbRaw *pRedoRaw = mndUserActionEncode(pNew);
S
Shengliang Guan 已提交
355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_READY);

  if (mndTransPrepare(pMnode, pTrans) != 0) {
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }

  mndTransDrop(pTrans);
  return 0;
}

S
Shengliang Guan 已提交
372
static SHashObj *mndDupDbHash(SHashObj *pOld) {
S
Shengliang Guan 已提交
373 374
  SHashObj *pNew =
      taosHashInit(taosHashGetSize(pOld), taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
S
Shengliang Guan 已提交
375 376 377 378 379 380 381 382 383 384 385
  if (pNew == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return NULL;
  }

  char *db = taosHashIterate(pOld, NULL);
  while (db != NULL) {
    int32_t len = strlen(db) + 1;
    if (taosHashPut(pNew, db, len, db, TSDB_DB_FNAME_LEN) != 0) {
      taosHashCancelIterate(pOld, db);
      taosHashCleanup(pNew);
S
Shengliang Guan 已提交
386
      terrno = TSDB_CODE_OUT_OF_MEMORY;
S
Shengliang Guan 已提交
387 388 389 390 391 392 393 394
      return NULL;
    }
    db = taosHashIterate(pOld, db);
  }

  return pNew;
}

S
Shengliang Guan 已提交
395 396
static int32_t mndProcessAlterUserReq(SNodeMsg *pReq) {
  SMnode       *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
397 398 399
  int32_t       code = -1;
  SUserObj     *pUser = NULL;
  SUserObj     *pOperUser = NULL;
S
Shengliang Guan 已提交
400
  SUserObj      newUser = {0};
S
Shengliang Guan 已提交
401 402
  SAlterUserReq alterReq = {0};

S
Shengliang Guan 已提交
403 404
  if (tDeserializeSAlterUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &alterReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
405
    goto _OVER;
S
Shengliang Guan 已提交
406
  }
S
Shengliang Guan 已提交
407

S
Shengliang Guan 已提交
408
  mDebug("user:%s, start to alter", alterReq.user);
S
Shengliang Guan 已提交
409

S
Shengliang Guan 已提交
410
  if (alterReq.user[0] == 0) {
S
Shengliang Guan 已提交
411
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
412
    goto _OVER;
S
Shengliang Guan 已提交
413 414
  }

S
Shengliang Guan 已提交
415
  pUser = mndAcquireUser(pMnode, alterReq.user);
S
Shengliang Guan 已提交
416 417
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
418
    goto _OVER;
S
Shengliang Guan 已提交
419 420
  }

S
Shengliang Guan 已提交
421
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
422 423
  if (pOperUser == NULL) {
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
424
    goto _OVER;
S
Shengliang Guan 已提交
425 426 427
  }

  memcpy(&newUser, pUser, sizeof(SUserObj));
S
Shengliang Guan 已提交
428 429

  taosRLockLatch(&pUser->lock);
S
Shengliang Guan 已提交
430 431
  newUser.readDbs = mndDupDbHash(pUser->readDbs);
  newUser.writeDbs = mndDupDbHash(pUser->writeDbs);
S
Shengliang Guan 已提交
432 433
  taosRUnLockLatch(&pUser->lock);

S
Shengliang Guan 已提交
434
  if (newUser.readDbs == NULL || newUser.writeDbs == NULL) {
435
    goto _OVER;
S
Shengliang Guan 已提交
436 437 438 439 440 441 442 443 444
  }

  int32_t len = strlen(alterReq.dbname) + 1;
  SDbObj *pDb = mndAcquireDb(pMnode, alterReq.dbname);
  mndReleaseDb(pMnode, pDb);

  if (alterReq.alterType == TSDB_ALTER_USER_PASSWD) {
    char pass[TSDB_PASSWORD_LEN + 1] = {0};
    taosEncryptPass_c((uint8_t *)alterReq.pass, strlen(alterReq.pass), pass);
445
    memcpy(newUser.pass, pass, TSDB_PASSWORD_LEN);
S
Shengliang Guan 已提交
446
  } else if (alterReq.alterType == TSDB_ALTER_USER_SUPERUSER) {
S
Shengliang Guan 已提交
447
    newUser.superUser = alterReq.superUser;
S
Shengliang Guan 已提交
448
  } else if (alterReq.alterType == TSDB_ALTER_USER_ADD_READ_DB) {
S
Shengliang Guan 已提交
449 450
    if (pDb == NULL) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
451
      goto _OVER;
S
Shengliang Guan 已提交
452 453 454
    }
    if (taosHashPut(newUser.readDbs, alterReq.dbname, len, alterReq.dbname, TSDB_DB_FNAME_LEN) != 0) {
      terrno = TSDB_CODE_OUT_OF_MEMORY;
455
      goto _OVER;
S
Shengliang Guan 已提交
456
    }
D
dapan 已提交
457
    newUser.authVersion++;
S
Shengliang Guan 已提交
458
  } else if (alterReq.alterType == TSDB_ALTER_USER_REMOVE_READ_DB) {
S
Shengliang Guan 已提交
459 460
    if (taosHashRemove(newUser.readDbs, alterReq.dbname, len) != 0) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
461
      goto _OVER;
S
Shengliang Guan 已提交
462
    }
D
dapan 已提交
463
    newUser.authVersion++;
S
Shengliang Guan 已提交
464
  } else if (alterReq.alterType == TSDB_ALTER_USER_CLEAR_READ_DB) {
S
Shengliang Guan 已提交
465
    taosHashClear(newUser.readDbs);
D
dapan 已提交
466
    newUser.authVersion++;
S
Shengliang Guan 已提交
467 468 469
  } else if (alterReq.alterType == TSDB_ALTER_USER_ADD_WRITE_DB) {
    if (pDb == NULL) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
470
      goto _OVER;
S
Shengliang Guan 已提交
471 472 473
    }
    if (taosHashPut(newUser.writeDbs, alterReq.dbname, len, alterReq.dbname, TSDB_DB_FNAME_LEN) != 0) {
      terrno = TSDB_CODE_OUT_OF_MEMORY;
474
      goto _OVER;
S
Shengliang Guan 已提交
475
    }
D
dapan 已提交
476
    newUser.authVersion++;
S
Shengliang Guan 已提交
477 478 479
  } else if (alterReq.alterType == TSDB_ALTER_USER_REMOVE_WRITE_DB) {
    if (taosHashRemove(newUser.writeDbs, alterReq.dbname, len) != 0) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
480
      goto _OVER;
S
Shengliang Guan 已提交
481
    }
D
dapan 已提交
482
    newUser.authVersion++;
S
Shengliang Guan 已提交
483
  } else if (alterReq.alterType == TSDB_ALTER_USER_CLEAR_WRITE_DB) {
S
Shengliang Guan 已提交
484
    taosHashClear(newUser.writeDbs);
D
dapan 已提交
485
    newUser.authVersion++;
S
Shengliang Guan 已提交
486 487
  } else {
    terrno = TSDB_CODE_MND_INVALID_ALTER_OPER;
488
    goto _OVER;
S
Shengliang Guan 已提交
489 490
  }

S
Shengliang Guan 已提交
491
  newUser.updateTime = taosGetTimestampMs();
S
Shengliang Guan 已提交
492

S
Shengliang Guan 已提交
493
  if (mndCheckAlterUserAuth(pOperUser, pUser, pDb, &alterReq) != 0) {
494
    goto _OVER;
S
Shengliang Guan 已提交
495 496
  }

S
Shengliang Guan 已提交
497
  code = mndAlterUser(pMnode, pUser, &newUser, pReq);
S
Shengliang Guan 已提交
498
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
499

500
_OVER:
S
Shengliang Guan 已提交
501 502
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to alter since %s", alterReq.user, terrstr());
S
Shengliang Guan 已提交
503 504
  }

S
Shengliang Guan 已提交
505 506
  mndReleaseUser(pMnode, pOperUser);
  mndReleaseUser(pMnode, pUser);
S
Shengliang Guan 已提交
507 508
  taosHashCleanup(newUser.writeDbs);
  taosHashCleanup(newUser.readDbs);
S
Shengliang Guan 已提交
509 510

  return code;
S
Shengliang Guan 已提交
511 512
}

S
Shengliang Guan 已提交
513
static int32_t mndDropUser(SMnode *pMnode, SNodeMsg *pReq, SUserObj *pUser) {
S
Shengliang Guan 已提交
514
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_DROP_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538
  if (pTrans == NULL) {
    mError("user:%s, failed to drop since %s", pUser->user, terrstr());
    return -1;
  }
  mDebug("trans:%d, used to drop user:%s", pTrans->id, pUser->user);

  SSdbRaw *pRedoRaw = mndUserActionEncode(pUser);
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_DROPPED);

  if (mndTransPrepare(pMnode, pTrans) != 0) {
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }

  mndTransDrop(pTrans);
  return 0;
}

S
Shengliang Guan 已提交
539 540
static int32_t mndProcessDropUserReq(SNodeMsg *pReq) {
  SMnode      *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
541 542 543 544 545
  int32_t      code = -1;
  SUserObj    *pUser = NULL;
  SUserObj    *pOperUser = NULL;
  SDropUserReq dropReq = {0};

S
Shengliang Guan 已提交
546 547
  if (tDeserializeSDropUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &dropReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
548
    goto _OVER;
S
Shengliang Guan 已提交
549
  }
S
Shengliang Guan 已提交
550

S
Shengliang Guan 已提交
551
  mDebug("user:%s, start to drop", dropReq.user);
S
Shengliang Guan 已提交
552

S
Shengliang Guan 已提交
553
  if (dropReq.user[0] == 0) {
S
Shengliang Guan 已提交
554
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
555
    goto _OVER;
S
Shengliang Guan 已提交
556 557
  }

S
Shengliang Guan 已提交
558
  pUser = mndAcquireUser(pMnode, dropReq.user);
S
Shengliang Guan 已提交
559 560
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
561
    goto _OVER;
S
Shengliang Guan 已提交
562 563
  }

S
Shengliang Guan 已提交
564
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
565 566
  if (pOperUser == NULL) {
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
567
    goto _OVER;
S
Shengliang Guan 已提交
568 569
  }

S
Shengliang Guan 已提交
570
  if (mndCheckDropUserAuth(pOperUser) != 0) {
571
    goto _OVER;
S
Shengliang Guan 已提交
572 573
  }

S
Shengliang Guan 已提交
574 575
  code = mndDropUser(pMnode, pReq, pUser);
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
576

577
_OVER:
S
Shengliang Guan 已提交
578 579
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to drop since %s", dropReq.user, terrstr());
S
Shengliang Guan 已提交
580 581
  }

S
Shengliang Guan 已提交
582 583 584 585
  mndReleaseUser(pMnode, pOperUser);
  mndReleaseUser(pMnode, pUser);

  return code;
S
Shengliang Guan 已提交
586 587
}

588
static int32_t mndSetUserAuthRsp(SMnode *pMnode, SUserObj *pUser, SGetUserAuthRsp *pRsp) {
D
dapan 已提交
589 590 591
  memcpy(pRsp->user, pUser->user, TSDB_USER_LEN);
  pRsp->superAuth = pUser->superUser;
  pRsp->version = pUser->authVersion;
592
  taosRLockLatch(&pUser->lock);
D
dapan 已提交
593 594
  pRsp->readDbs = mndDupDbHash(pUser->readDbs);
  pRsp->writeDbs = mndDupDbHash(pUser->writeDbs);
595
  taosRUnLockLatch(&pUser->lock);
D
dapan 已提交
596 597 598 599 600
  pRsp->createdDbs = taosHashInit(4, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_NO_LOCK);
  if (NULL == pRsp->createdDbs) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return -1;
  }
601

D
dapan 已提交
602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619
  SSdb *pSdb = pMnode->pSdb;
  void *pIter = NULL;
  while (1) {
    SDbObj *pDb = NULL;
    pIter = sdbFetch(pSdb, SDB_DB, pIter, (void **)&pDb);
    if (pIter == NULL) break;

    if (strcmp(pDb->createUser, pUser->user) == 0) {
      int32_t len = strlen(pDb->name) + 1;
      taosHashPut(pRsp->createdDbs, pDb->name, len, pDb->name, len);
    }

    sdbRelease(pSdb, pDb);
  }

  return 0;
}

S
Shengliang Guan 已提交
620 621
static int32_t mndProcessGetUserAuthReq(SNodeMsg *pReq) {
  SMnode         *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
622 623 624 625 626
  int32_t         code = -1;
  SUserObj       *pUser = NULL;
  SGetUserAuthReq authReq = {0};
  SGetUserAuthRsp authRsp = {0};

S
Shengliang Guan 已提交
627 628
  if (tDeserializeSGetUserAuthReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &authReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
629
    goto _OVER;
S
Shengliang Guan 已提交
630
  }
S
Shengliang Guan 已提交
631 632 633 634 635 636

  mTrace("user:%s, start to get auth", authReq.user);

  pUser = mndAcquireUser(pMnode, authReq.user);
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
637
    goto _OVER;
S
Shengliang Guan 已提交
638 639
  }

D
dapan 已提交
640 641 642
  code = mndSetUserAuthRsp(pMnode, pUser, &authRsp);
  if (code) {
    goto _OVER;
S
Shengliang Guan 已提交
643 644
  }

S
Shengliang Guan 已提交
645
  int32_t contLen = tSerializeSGetUserAuthRsp(NULL, 0, &authRsp);
S
Shengliang Guan 已提交
646 647 648
  void   *pRsp = rpcMallocCont(contLen);
  if (pRsp == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
649
    goto _OVER;
S
Shengliang Guan 已提交
650 651
  }

S
Shengliang Guan 已提交
652
  tSerializeSGetUserAuthRsp(pRsp, contLen, &authRsp);
S
Shengliang Guan 已提交
653

S
Shengliang Guan 已提交
654 655
  pReq->pRsp = pRsp;
  pReq->rspLen = contLen;
S
Shengliang Guan 已提交
656 657
  code = 0;

658
_OVER:
659

S
Shengliang Guan 已提交
660
  mndReleaseUser(pMnode, pUser);
S
Shengliang Guan 已提交
661
  tFreeSGetUserAuthRsp(&authRsp);
S
Shengliang Guan 已提交
662 663 664 665

  return code;
}

666
static int32_t mndRetrieveUsers(SNodeMsg *pReq, SShowObj *pShow, SSDataBlock *pBlock, int32_t rows) {
S
Shengliang Guan 已提交
667
  SMnode   *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
668 669 670 671 672 673 674 675 676 677 678
  SSdb     *pSdb = pMnode->pSdb;
  int32_t   numOfRows = 0;
  SUserObj *pUser = NULL;
  int32_t   cols = 0;
  char     *pWrite;

  while (numOfRows < rows) {
    pShow->pIter = sdbFetch(pSdb, SDB_USER, pShow->pIter, (void **)&pUser);
    if (pShow->pIter == NULL) break;

    cols = 0;
679
    SColumnInfoData *pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
680 681

    char name[TSDB_USER_LEN + VARSTR_HEADER_SIZE] = {0};
682
    STR_WITH_MAXSIZE_TO_VARSTR(name, pUser->user, pShow->pMeta->pSchemas[cols].bytes);
683

684
    colDataAppend(pColInfo, numOfRows, (const char *)name, false);
685

wafwerar's avatar
wafwerar 已提交
686 687
    cols++;
    pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
688

689 690
    const char *src = pUser->superUser ? "super" : "normal";
    char        b[10 + VARSTR_HEADER_SIZE] = {0};
691
    STR_WITH_SIZE_TO_VARSTR(b, src, strlen(src));
692
    colDataAppend(pColInfo, numOfRows, (const char *)b, false);
693

wafwerar's avatar
wafwerar 已提交
694 695
    cols++;
    pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
696
    colDataAppend(pColInfo, numOfRows, (const char *)&pUser->createdTime, false);
S
Shengliang Guan 已提交
697 698 699 700 701

    numOfRows++;
    sdbRelease(pSdb, pUser);
  }

702
  pShow->numOfRows += numOfRows;
S
Shengliang Guan 已提交
703 704 705 706 707 708
  return numOfRows;
}

static void mndCancelGetNextUser(SMnode *pMnode, void *pIter) {
  SSdb *pSdb = pMnode->pSdb;
  sdbCancelFetch(pSdb, pIter);
S
Shengliang Guan 已提交
709
}
D
dapan 已提交
710

711 712
int32_t mndValidateUserAuthInfo(SMnode *pMnode, SUserAuthVersion *pUsers, int32_t numOfUses, void **ppRsp,
                                int32_t *pRspLen) {
D
dapan 已提交
713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731
  SUserAuthBatchRsp batchRsp = {0};
  batchRsp.pArray = taosArrayInit(numOfUses, sizeof(SGetUserAuthRsp));
  if (batchRsp.pArray == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return -1;
  }

  int32_t code = 0;
  for (int32_t i = 0; i < numOfUses; ++i) {
    SUserObj *pUser = mndAcquireUser(pMnode, pUsers[i].user);
    if (pUser == NULL) {
      mError("user:%s, failed to auth user since %s", pUsers[i].user, terrstr());
      continue;
    }

    if (pUser->authVersion <= pUsers[i].version) {
      mndReleaseUser(pMnode, pUser);
      continue;
    }
732

D
dapan 已提交
733 734 735 736 737 738 739 740 741 742 743 744 745 746 747
    SGetUserAuthRsp rsp = {0};
    code = mndSetUserAuthRsp(pMnode, pUser, &rsp);
    if (code) {
      mndReleaseUser(pMnode, pUser);
      tFreeSGetUserAuthRsp(&rsp);
      goto _OVER;
    }

    taosArrayPush(batchRsp.pArray, &rsp);
    mndReleaseUser(pMnode, pUser);
  }

  if (taosArrayGetSize(batchRsp.pArray) <= 0) {
    *ppRsp = NULL;
    *pRspLen = 0;
748

D
dapan 已提交
749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771
    tFreeSUserAuthBatchRsp(&batchRsp);
    return 0;
  }

  int32_t rspLen = tSerializeSUserAuthBatchRsp(NULL, 0, &batchRsp);
  void   *pRsp = taosMemoryMalloc(rspLen);
  if (pRsp == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    tFreeSUserAuthBatchRsp(&batchRsp);
    return -1;
  }
  tSerializeSUserAuthBatchRsp(pRsp, rspLen, &batchRsp);

  *ppRsp = pRsp;
  *pRspLen = rspLen;

  tFreeSUserAuthBatchRsp(&batchRsp);
  return 0;

_OVER:

  *ppRsp = NULL;
  *pRspLen = 0;
772

D
dapan 已提交
773 774 775
  tFreeSUserAuthBatchRsp(&batchRsp);
  return code;
}