mndUser.c 23.1 KB
Newer Older
H
refact  
Hongze Cheng 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * Copyright (c) 2019 TAOS Data, Inc. <jhtao@taosdata.com>
 *
 * This program is free software: you can use, redistribute, and/or modify
 * it under the terms of the GNU Affero General Public License, version 3
 * or later ("AGPL"), as published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.
 *
 * You should have received a copy of the GNU Affero General Public License
 * along with this program. If not, see <http://www.gnu.org/licenses/>.
 */

S
Shengliang Guan 已提交
16
#define _DEFAULT_SOURCE
S
Shengliang Guan 已提交
17
#include "mndUser.h"
S
Shengliang Guan 已提交
18
#include "mndAuth.h"
S
Shengliang Guan 已提交
19
#include "mndDb.h"
S
Shengliang Guan 已提交
20
#include "mndShow.h"
S
Shengliang Guan 已提交
21
#include "mndTrans.h"
S
tbase64  
Shengliang Guan 已提交
22
#include "tbase64.h"
S
Shengliang Guan 已提交
23

24 25
#define USER_VER_NUMBER   1
#define USER_RESERVE_SIZE 64
S
Shengliang Guan 已提交
26

S
Shengliang Guan 已提交
27 28 29 30
static int32_t  mndCreateDefaultUsers(SMnode *pMnode);
static SSdbRow *mndUserActionDecode(SSdbRaw *pRaw);
static int32_t  mndUserActionInsert(SSdb *pSdb, SUserObj *pUser);
static int32_t  mndUserActionDelete(SSdb *pSdb, SUserObj *pUser);
S
Shengliang Guan 已提交
31
static int32_t  mndUserActionUpdate(SSdb *pSdb, SUserObj *pOld, SUserObj *pNew);
S
Shengliang Guan 已提交
32 33 34 35 36
static int32_t  mndCreateUser(SMnode *pMnode, char *acct, SCreateUserReq *pCreate, SNodeMsg *pReq);
static int32_t  mndProcessCreateUserReq(SNodeMsg *pReq);
static int32_t  mndProcessAlterUserReq(SNodeMsg *pReq);
static int32_t  mndProcessDropUserReq(SNodeMsg *pReq);
static int32_t  mndProcessGetUserAuthReq(SNodeMsg *pReq);
37
static int32_t  mndRetrieveUsers(SNodeMsg *pReq, SShowObj *pShow, SSDataBlock *pBlock, int32_t rows);
S
Shengliang Guan 已提交
38
static void     mndCancelGetNextUser(SMnode *pMnode, void *pIter);
S
Shengliang Guan 已提交
39 40

int32_t mndInitUser(SMnode *pMnode) {
S
Shengliang Guan 已提交
41 42 43 44 45 46 47 48 49 50
  SSdbTable table = {
      .sdbType = SDB_USER,
      .keyType = SDB_KEY_BINARY,
      .deployFp = (SdbDeployFp)mndCreateDefaultUsers,
      .encodeFp = (SdbEncodeFp)mndUserActionEncode,
      .decodeFp = (SdbDecodeFp)mndUserActionDecode,
      .insertFp = (SdbInsertFp)mndUserActionInsert,
      .updateFp = (SdbUpdateFp)mndUserActionUpdate,
      .deleteFp = (SdbDeleteFp)mndUserActionDelete,
  };
S
Shengliang Guan 已提交
51

S
Shengliang Guan 已提交
52 53 54
  mndSetMsgHandle(pMnode, TDMT_MND_CREATE_USER, mndProcessCreateUserReq);
  mndSetMsgHandle(pMnode, TDMT_MND_ALTER_USER, mndProcessAlterUserReq);
  mndSetMsgHandle(pMnode, TDMT_MND_DROP_USER, mndProcessDropUserReq);
S
Shengliang Guan 已提交
55
  mndSetMsgHandle(pMnode, TDMT_MND_GET_USER_AUTH, mndProcessGetUserAuthReq);
S
Shengliang Guan 已提交
56

S
Shengliang Guan 已提交
57 58
  mndAddShowRetrieveHandle(pMnode, TSDB_MGMT_TABLE_USER, mndRetrieveUsers);
  mndAddShowFreeIterHandle(pMnode, TSDB_MGMT_TABLE_USER, mndCancelGetNextUser);
S
Shengliang Guan 已提交
59 60 61 62 63 64 65
  return sdbSetTable(pMnode->pSdb, table);
}

void mndCleanupUser(SMnode *pMnode) {}

static int32_t mndCreateDefaultUser(SMnode *pMnode, char *acct, char *user, char *pass) {
  SUserObj userObj = {0};
S
Shengliang Guan 已提交
66
  taosEncryptPass_c((uint8_t *)pass, strlen(pass), userObj.pass);
S
Shengliang Guan 已提交
67 68 69 70 71 72
  tstrncpy(userObj.user, user, TSDB_USER_LEN);
  tstrncpy(userObj.acct, acct, TSDB_USER_LEN);
  userObj.createdTime = taosGetTimestampMs();
  userObj.updateTime = userObj.createdTime;

  if (strcmp(user, TSDB_DEFAULT_USER) == 0) {
73
    userObj.superUser = 1;
S
Shengliang Guan 已提交
74 75 76 77 78 79
  }

  SSdbRaw *pRaw = mndUserActionEncode(&userObj);
  if (pRaw == NULL) return -1;
  sdbSetRawStatus(pRaw, SDB_STATUS_READY);

S
Shengliang Guan 已提交
80
  mDebug("user:%s, will be created while deploy sdb, raw:%p", userObj.user, pRaw);
S
Shengliang Guan 已提交
81 82 83 84 85 86 87 88 89 90 91
  return sdbWrite(pMnode->pSdb, pRaw);
}

static int32_t mndCreateDefaultUsers(SMnode *pMnode) {
  if (mndCreateDefaultUser(pMnode, TSDB_DEFAULT_USER, TSDB_DEFAULT_USER, TSDB_DEFAULT_PASS) != 0) {
    return -1;
  }

  return 0;
}

92
SSdbRaw *mndUserActionEncode(SUserObj *pUser) {
93 94
  terrno = TSDB_CODE_OUT_OF_MEMORY;

S
Shengliang Guan 已提交
95 96
  int32_t numOfReadDbs = taosHashGetSize(pUser->readDbs);
  int32_t numOfWriteDbs = taosHashGetSize(pUser->writeDbs);
97
  int32_t size = sizeof(SUserObj) + USER_RESERVE_SIZE + (numOfReadDbs + numOfWriteDbs) * TSDB_DB_FNAME_LEN;
S
Shengliang Guan 已提交
98

99
  SSdbRaw *pRaw = sdbAllocRaw(SDB_USER, USER_VER_NUMBER, size);
100
  if (pRaw == NULL) goto _OVER;
S
Shengliang Guan 已提交
101 102

  int32_t dataPos = 0;
103 104 105 106 107 108 109 110
  SDB_SET_BINARY(pRaw, dataPos, pUser->user, TSDB_USER_LEN, _OVER)
  SDB_SET_BINARY(pRaw, dataPos, pUser->pass, TSDB_PASSWORD_LEN, _OVER)
  SDB_SET_BINARY(pRaw, dataPos, pUser->acct, TSDB_USER_LEN, _OVER)
  SDB_SET_INT64(pRaw, dataPos, pUser->createdTime, _OVER)
  SDB_SET_INT64(pRaw, dataPos, pUser->updateTime, _OVER)
  SDB_SET_INT8(pRaw, dataPos, pUser->superUser, _OVER)
  SDB_SET_INT32(pRaw, dataPos, numOfReadDbs, _OVER)
  SDB_SET_INT32(pRaw, dataPos, numOfWriteDbs, _OVER)
111 112 113

  char *db = taosHashIterate(pUser->readDbs, NULL);
  while (db != NULL) {
114
    SDB_SET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER);
115 116 117 118 119
    db = taosHashIterate(pUser->readDbs, db);
  }

  db = taosHashIterate(pUser->writeDbs, NULL);
  while (db != NULL) {
120
    SDB_SET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER);
121 122 123
    db = taosHashIterate(pUser->writeDbs, db);
  }

124 125
  SDB_SET_RESERVE(pRaw, dataPos, USER_RESERVE_SIZE, _OVER)
  SDB_SET_DATALEN(pRaw, dataPos, _OVER)
126 127 128

  terrno = 0;

129
_OVER:
130 131 132 133 134
  if (terrno != 0) {
    mError("user:%s, failed to encode to raw:%p since %s", pUser->user, pRaw, terrstr());
    sdbFreeRaw(pRaw);
    return NULL;
  }
S
Shengliang Guan 已提交
135

S
Shengliang Guan 已提交
136
  mTrace("user:%s, encode to raw:%p, row:%p", pUser->user, pRaw, pUser);
S
Shengliang Guan 已提交
137
  return pRaw;
S
Shengliang Guan 已提交
138 139
}

S
Shengliang Guan 已提交
140
static SSdbRow *mndUserActionDecode(SSdbRaw *pRaw) {
141 142
  terrno = TSDB_CODE_OUT_OF_MEMORY;

S
Shengliang Guan 已提交
143
  int8_t sver = 0;
144
  if (sdbGetRawSoftVer(pRaw, &sver) != 0) goto _OVER;
S
Shengliang Guan 已提交
145

146
  if (sver != USER_VER_NUMBER) {
S
Shengliang Guan 已提交
147
    terrno = TSDB_CODE_SDB_INVALID_DATA_VER;
148
    goto _OVER;
S
Shengliang Guan 已提交
149
  }
S
Shengliang Guan 已提交
150

151
  SSdbRow *pRow = sdbAllocRow(sizeof(SUserObj));
152
  if (pRow == NULL) goto _OVER;
153

S
Shengliang Guan 已提交
154
  SUserObj *pUser = sdbGetRowObj(pRow);
155
  if (pUser == NULL) goto _OVER;
156

S
Shengliang Guan 已提交
157
  int32_t dataPos = 0;
158 159 160 161 162 163
  SDB_GET_BINARY(pRaw, dataPos, pUser->user, TSDB_USER_LEN, _OVER)
  SDB_GET_BINARY(pRaw, dataPos, pUser->pass, TSDB_PASSWORD_LEN, _OVER)
  SDB_GET_BINARY(pRaw, dataPos, pUser->acct, TSDB_USER_LEN, _OVER)
  SDB_GET_INT64(pRaw, dataPos, &pUser->createdTime, _OVER)
  SDB_GET_INT64(pRaw, dataPos, &pUser->updateTime, _OVER)
  SDB_GET_INT8(pRaw, dataPos, &pUser->superUser, _OVER)
164 165 166

  int32_t numOfReadDbs = 0;
  int32_t numOfWriteDbs = 0;
167 168
  SDB_GET_INT32(pRaw, dataPos, &numOfReadDbs, _OVER)
  SDB_GET_INT32(pRaw, dataPos, &numOfWriteDbs, _OVER)
S
Shengliang Guan 已提交
169 170 171
  pUser->readDbs = taosHashInit(numOfReadDbs, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
  pUser->writeDbs =
      taosHashInit(numOfWriteDbs, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
172
  if (pUser->readDbs == NULL || pUser->writeDbs == NULL) goto _OVER;
173 174 175

  for (int32_t i = 0; i < numOfReadDbs; ++i) {
    char db[TSDB_DB_FNAME_LEN] = {0};
176
    SDB_GET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER)
177 178 179 180 181 182
    int32_t len = strlen(db) + 1;
    taosHashPut(pUser->readDbs, db, len, db, TSDB_DB_FNAME_LEN);
  }

  for (int32_t i = 0; i < numOfWriteDbs; ++i) {
    char db[TSDB_DB_FNAME_LEN] = {0};
183
    SDB_GET_BINARY(pRaw, dataPos, db, TSDB_DB_FNAME_LEN, _OVER)
184 185 186 187
    int32_t len = strlen(db) + 1;
    taosHashPut(pUser->writeDbs, db, len, db, TSDB_DB_FNAME_LEN);
  }

188
  SDB_GET_RESERVE(pRaw, dataPos, USER_RESERVE_SIZE, _OVER)
189 190 191

  terrno = 0;

192
_OVER:
193 194
  if (terrno != 0) {
    mError("user:%s, failed to decode from raw:%p since %s", pUser->user, pRaw, terrstr());
195 196
    taosHashCleanup(pUser->readDbs);
    taosHashCleanup(pUser->writeDbs);
wafwerar's avatar
wafwerar 已提交
197
    taosMemoryFreeClear(pRow);
198 199
    return NULL;
  }
S
Shengliang Guan 已提交
200

S
Shengliang Guan 已提交
201
  mTrace("user:%s, decode from raw:%p, row:%p", pUser->user, pRaw, pUser);
S
Shengliang Guan 已提交
202
  return pRow;
S
Shengliang Guan 已提交
203
}
S
Shengliang Guan 已提交
204

S
Shengliang Guan 已提交
205
static int32_t mndUserActionInsert(SSdb *pSdb, SUserObj *pUser) {
S
Shengliang Guan 已提交
206
  mTrace("user:%s, perform insert action, row:%p", pUser->user, pUser);
S
Shengliang Guan 已提交
207

S
Shengliang Guan 已提交
208 209
  SAcctObj *pAcct = sdbAcquire(pSdb, SDB_ACCT, pUser->acct);
  if (pAcct == NULL) {
S
Shengliang Guan 已提交
210
    terrno = TSDB_CODE_MND_ACCT_NOT_EXIST;
S
Shengliang Guan 已提交
211
    mError("user:%s, failed to perform insert action since %s", pUser->user, terrstr());
S
Shengliang Guan 已提交
212
    return -1;
S
Shengliang Guan 已提交
213
  }
S
Shengliang Guan 已提交
214 215
  pUser->acctId = pAcct->acctId;
  sdbRelease(pSdb, pAcct);
S
Shengliang Guan 已提交
216

S
Shengliang Guan 已提交
217 218
  return 0;
}
S
Shengliang Guan 已提交
219

S
Shengliang Guan 已提交
220
static int32_t mndUserActionDelete(SSdb *pSdb, SUserObj *pUser) {
S
Shengliang Guan 已提交
221
  mTrace("user:%s, perform delete action, row:%p", pUser->user, pUser);
222 223
  taosHashCleanup(pUser->readDbs);
  taosHashCleanup(pUser->writeDbs);
224 225
  pUser->readDbs = NULL;
  pUser->writeDbs = NULL;
S
Shengliang Guan 已提交
226 227 228
  return 0;
}

S
Shengliang Guan 已提交
229
static int32_t mndUserActionUpdate(SSdb *pSdb, SUserObj *pOld, SUserObj *pNew) {
S
Shengliang Guan 已提交
230
  mTrace("user:%s, perform update action, old row:%p new row:%p", pOld->user, pOld, pNew);
S
Shengliang Guan 已提交
231 232
  memcpy(pOld->pass, pNew->pass, TSDB_PASSWORD_LEN);
  pOld->updateTime = pNew->updateTime;
233

wafwerar's avatar
wafwerar 已提交
234 235
  TSWAP(pOld->readDbs, pNew->readDbs);
  TSWAP(pOld->writeDbs, pNew->writeDbs);
236

S
Shengliang Guan 已提交
237 238 239
  return 0;
}

240
SUserObj *mndAcquireUser(SMnode *pMnode, const char *userName) {
S
Shengliang Guan 已提交
241 242 243
  SSdb     *pSdb = pMnode->pSdb;
  SUserObj *pUser = sdbAcquire(pSdb, SDB_USER, userName);
  if (pUser == NULL) {
S
Shengliang Guan 已提交
244
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
S
Shengliang Guan 已提交
245 246
  }
  return pUser;
S
Shengliang Guan 已提交
247
}
S
Shengliang Guan 已提交
248

S
Shengliang Guan 已提交
249 250 251
void mndReleaseUser(SMnode *pMnode, SUserObj *pUser) {
  SSdb *pSdb = pMnode->pSdb;
  sdbRelease(pSdb, pUser);
S
Shengliang Guan 已提交
252 253
}

S
Shengliang Guan 已提交
254
static int32_t mndCreateUser(SMnode *pMnode, char *acct, SCreateUserReq *pCreate, SNodeMsg *pReq) {
S
Shengliang Guan 已提交
255
  SUserObj userObj = {0};
S
Shengliang Guan 已提交
256 257
  taosEncryptPass_c((uint8_t *)pCreate->pass, strlen(pCreate->pass), userObj.pass);
  tstrncpy(userObj.user, pCreate->user, TSDB_USER_LEN);
S
Shengliang Guan 已提交
258 259 260
  tstrncpy(userObj.acct, acct, TSDB_USER_LEN);
  userObj.createdTime = taosGetTimestampMs();
  userObj.updateTime = userObj.createdTime;
S
Shengliang Guan 已提交
261
  userObj.superUser = pCreate->superUser;
S
Shengliang Guan 已提交
262

S
Shengliang Guan 已提交
263
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_CREATE_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
264
  if (pTrans == NULL) {
S
Shengliang Guan 已提交
265
    mError("user:%s, failed to create since %s", pCreate->user, terrstr());
S
Shengliang Guan 已提交
266 267
    return -1;
  }
S
Shengliang Guan 已提交
268
  mDebug("trans:%d, used to create user:%s", pTrans->id, pCreate->user);
S
Shengliang Guan 已提交
269

S
Shengliang Guan 已提交
270
  SSdbRaw *pRedoRaw = mndUserActionEncode(&userObj);
S
Shengliang Guan 已提交
271
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
S
Shengliang Guan 已提交
272
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
S
Shengliang Guan 已提交
273
    mndTransDrop(pTrans);
S
Shengliang Guan 已提交
274
    return -1;
S
Shengliang Guan 已提交
275
  }
S
Shengliang Guan 已提交
276 277
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_READY);

S
Shengliang Guan 已提交
278
  if (mndTransPrepare(pMnode, pTrans) != 0) {
S
Shengliang Guan 已提交
279
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
S
Shengliang Guan 已提交
280
    mndTransDrop(pTrans);
S
Shengliang Guan 已提交
281
    return -1;
S
Shengliang Guan 已提交
282 283
  }

S
Shengliang Guan 已提交
284
  mndTransDrop(pTrans);
S
Shengliang Guan 已提交
285
  return 0;
S
Shengliang Guan 已提交
286 287
}

S
Shengliang Guan 已提交
288 289
static int32_t mndProcessCreateUserReq(SNodeMsg *pReq) {
  SMnode        *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
290 291 292 293 294
  int32_t        code = -1;
  SUserObj      *pUser = NULL;
  SUserObj      *pOperUser = NULL;
  SCreateUserReq createReq = {0};

S
Shengliang Guan 已提交
295 296
  if (tDeserializeSCreateUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &createReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
297
    goto _OVER;
S
Shengliang Guan 已提交
298
  }
S
Shengliang Guan 已提交
299

S
Shengliang Guan 已提交
300
  mDebug("user:%s, start to create", createReq.user);
S
Shengliang Guan 已提交
301

S
Shengliang Guan 已提交
302
  if (createReq.user[0] == 0) {
S
Shengliang Guan 已提交
303
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
304
    goto _OVER;
S
Shengliang Guan 已提交
305 306
  }

S
Shengliang Guan 已提交
307
  if (createReq.pass[0] == 0) {
S
Shengliang Guan 已提交
308
    terrno = TSDB_CODE_MND_INVALID_PASS_FORMAT;
309
    goto _OVER;
S
Shengliang Guan 已提交
310 311
  }

S
Shengliang Guan 已提交
312
  pUser = mndAcquireUser(pMnode, createReq.user);
S
Shengliang Guan 已提交
313
  if (pUser != NULL) {
S
Shengliang Guan 已提交
314
    terrno = TSDB_CODE_MND_USER_ALREADY_EXIST;
315
    goto _OVER;
S
Shengliang Guan 已提交
316 317
  }

S
Shengliang Guan 已提交
318
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
319
  if (pOperUser == NULL) {
S
Shengliang Guan 已提交
320
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
321
    goto _OVER;
S
Shengliang Guan 已提交
322 323
  }

S
Shengliang Guan 已提交
324
  if (mndCheckCreateUserAuth(pOperUser) != 0) {
325
    goto _OVER;
S
Shengliang Guan 已提交
326 327 328
  }

  code = mndCreateUser(pMnode, pOperUser->acct, &createReq, pReq);
S
Shengliang Guan 已提交
329
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
330

331
_OVER:
S
Shengliang Guan 已提交
332 333
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to create since %s", createReq.user, terrstr());
S
Shengliang Guan 已提交
334 335
  }

S
Shengliang Guan 已提交
336 337 338 339
  mndReleaseUser(pMnode, pUser);
  mndReleaseUser(pMnode, pOperUser);

  return code;
S
Shengliang Guan 已提交
340 341
}

S
Shengliang Guan 已提交
342
static int32_t mndAlterUser(SMnode *pMnode, SUserObj *pOld, SUserObj *pNew, SNodeMsg *pReq) {
S
Shengliang Guan 已提交
343
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_ALTER_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
344
  if (pTrans == NULL) {
S
Shengliang Guan 已提交
345
    mError("user:%s, failed to alter since %s", pOld->user, terrstr());
S
Shengliang Guan 已提交
346 347
    return -1;
  }
S
Shengliang Guan 已提交
348
  mDebug("trans:%d, used to alter user:%s", pTrans->id, pOld->user);
S
Shengliang Guan 已提交
349

S
Shengliang Guan 已提交
350
  SSdbRaw *pRedoRaw = mndUserActionEncode(pNew);
S
Shengliang Guan 已提交
351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_READY);

  if (mndTransPrepare(pMnode, pTrans) != 0) {
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }

  mndTransDrop(pTrans);
  return 0;
}

S
Shengliang Guan 已提交
368
static SHashObj *mndDupDbHash(SHashObj *pOld) {
S
Shengliang Guan 已提交
369 370
  SHashObj *pNew =
      taosHashInit(taosHashGetSize(pOld), taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_ENTRY_LOCK);
S
Shengliang Guan 已提交
371 372 373 374 375 376 377 378 379 380 381
  if (pNew == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return NULL;
  }

  char *db = taosHashIterate(pOld, NULL);
  while (db != NULL) {
    int32_t len = strlen(db) + 1;
    if (taosHashPut(pNew, db, len, db, TSDB_DB_FNAME_LEN) != 0) {
      taosHashCancelIterate(pOld, db);
      taosHashCleanup(pNew);
S
Shengliang Guan 已提交
382
      terrno = TSDB_CODE_OUT_OF_MEMORY;
S
Shengliang Guan 已提交
383 384 385 386 387 388 389 390
      return NULL;
    }
    db = taosHashIterate(pOld, db);
  }

  return pNew;
}

S
Shengliang Guan 已提交
391 392
static int32_t mndProcessAlterUserReq(SNodeMsg *pReq) {
  SMnode       *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
393 394 395
  int32_t       code = -1;
  SUserObj     *pUser = NULL;
  SUserObj     *pOperUser = NULL;
S
Shengliang Guan 已提交
396
  SUserObj      newUser = {0};
S
Shengliang Guan 已提交
397 398
  SAlterUserReq alterReq = {0};

S
Shengliang Guan 已提交
399 400
  if (tDeserializeSAlterUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &alterReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
401
    goto _OVER;
S
Shengliang Guan 已提交
402
  }
S
Shengliang Guan 已提交
403

S
Shengliang Guan 已提交
404
  mDebug("user:%s, start to alter", alterReq.user);
S
Shengliang Guan 已提交
405

S
Shengliang Guan 已提交
406
  if (alterReq.user[0] == 0) {
S
Shengliang Guan 已提交
407
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
408
    goto _OVER;
S
Shengliang Guan 已提交
409 410
  }

S
Shengliang Guan 已提交
411
  if (alterReq.pass[0] == 0) {
S
Shengliang Guan 已提交
412
    terrno = TSDB_CODE_MND_INVALID_PASS_FORMAT;
413
    goto _OVER;
S
Shengliang Guan 已提交
414 415
  }

S
Shengliang Guan 已提交
416
  pUser = mndAcquireUser(pMnode, alterReq.user);
S
Shengliang Guan 已提交
417 418
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
419
    goto _OVER;
S
Shengliang Guan 已提交
420 421
  }

S
Shengliang Guan 已提交
422
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
423 424
  if (pOperUser == NULL) {
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
425
    goto _OVER;
S
Shengliang Guan 已提交
426 427 428
  }

  memcpy(&newUser, pUser, sizeof(SUserObj));
S
Shengliang Guan 已提交
429 430 431
  newUser.readDbs = mndDupDbHash(pUser->readDbs);
  newUser.writeDbs = mndDupDbHash(pUser->writeDbs);
  if (newUser.readDbs == NULL || newUser.writeDbs == NULL) {
432
    goto _OVER;
S
Shengliang Guan 已提交
433 434 435 436 437 438 439 440 441
  }

  int32_t len = strlen(alterReq.dbname) + 1;
  SDbObj *pDb = mndAcquireDb(pMnode, alterReq.dbname);
  mndReleaseDb(pMnode, pDb);

  if (alterReq.alterType == TSDB_ALTER_USER_PASSWD) {
    char pass[TSDB_PASSWORD_LEN + 1] = {0};
    taosEncryptPass_c((uint8_t *)alterReq.pass, strlen(alterReq.pass), pass);
442
    memcpy(newUser.pass, pass, TSDB_PASSWORD_LEN);
S
Shengliang Guan 已提交
443
  } else if (alterReq.alterType == TSDB_ALTER_USER_SUPERUSER) {
S
Shengliang Guan 已提交
444
    newUser.superUser = alterReq.superUser;
S
Shengliang Guan 已提交
445
  } else if (alterReq.alterType == TSDB_ALTER_USER_ADD_READ_DB) {
S
Shengliang Guan 已提交
446 447
    if (pDb == NULL) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
448
      goto _OVER;
S
Shengliang Guan 已提交
449 450 451
    }
    if (taosHashPut(newUser.readDbs, alterReq.dbname, len, alterReq.dbname, TSDB_DB_FNAME_LEN) != 0) {
      terrno = TSDB_CODE_OUT_OF_MEMORY;
452
      goto _OVER;
S
Shengliang Guan 已提交
453
    }
D
dapan 已提交
454
    newUser.authVersion++;
S
Shengliang Guan 已提交
455
  } else if (alterReq.alterType == TSDB_ALTER_USER_REMOVE_READ_DB) {
S
Shengliang Guan 已提交
456 457
    if (taosHashRemove(newUser.readDbs, alterReq.dbname, len) != 0) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
458
      goto _OVER;
S
Shengliang Guan 已提交
459
    }
D
dapan 已提交
460
    newUser.authVersion++;
S
Shengliang Guan 已提交
461
  } else if (alterReq.alterType == TSDB_ALTER_USER_CLEAR_READ_DB) {
S
Shengliang Guan 已提交
462
    taosHashClear(newUser.readDbs);
D
dapan 已提交
463
    newUser.authVersion++;
S
Shengliang Guan 已提交
464 465 466
  } else if (alterReq.alterType == TSDB_ALTER_USER_ADD_WRITE_DB) {
    if (pDb == NULL) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
467
      goto _OVER;
S
Shengliang Guan 已提交
468 469 470
    }
    if (taosHashPut(newUser.writeDbs, alterReq.dbname, len, alterReq.dbname, TSDB_DB_FNAME_LEN) != 0) {
      terrno = TSDB_CODE_OUT_OF_MEMORY;
471
      goto _OVER;
S
Shengliang Guan 已提交
472
    }
D
dapan 已提交
473
    newUser.authVersion++;
S
Shengliang Guan 已提交
474 475 476
  } else if (alterReq.alterType == TSDB_ALTER_USER_REMOVE_WRITE_DB) {
    if (taosHashRemove(newUser.writeDbs, alterReq.dbname, len) != 0) {
      terrno = TSDB_CODE_MND_DB_NOT_EXIST;
477
      goto _OVER;
S
Shengliang Guan 已提交
478
    }
D
dapan 已提交
479
    newUser.authVersion++;
S
Shengliang Guan 已提交
480
  } else if (alterReq.alterType == TSDB_ALTER_USER_CLEAR_WRITE_DB) {
S
Shengliang Guan 已提交
481
    taosHashClear(newUser.writeDbs);
D
dapan 已提交
482
    newUser.authVersion++;
S
Shengliang Guan 已提交
483 484
  } else {
    terrno = TSDB_CODE_MND_INVALID_ALTER_OPER;
485
    goto _OVER;
S
Shengliang Guan 已提交
486 487
  }

S
Shengliang Guan 已提交
488
  newUser.updateTime = taosGetTimestampMs();
S
Shengliang Guan 已提交
489

S
Shengliang Guan 已提交
490
  if (mndCheckAlterUserAuth(pOperUser, pUser, pDb, &alterReq) != 0) {
491
    goto _OVER;
S
Shengliang Guan 已提交
492 493
  }

S
Shengliang Guan 已提交
494
  code = mndAlterUser(pMnode, pUser, &newUser, pReq);
S
Shengliang Guan 已提交
495
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
496

497
_OVER:
S
Shengliang Guan 已提交
498 499
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to alter since %s", alterReq.user, terrstr());
S
Shengliang Guan 已提交
500 501
  }

S
Shengliang Guan 已提交
502 503
  mndReleaseUser(pMnode, pOperUser);
  mndReleaseUser(pMnode, pUser);
S
Shengliang Guan 已提交
504 505
  taosHashCleanup(newUser.writeDbs);
  taosHashCleanup(newUser.readDbs);
S
Shengliang Guan 已提交
506 507

  return code;
S
Shengliang Guan 已提交
508 509
}

S
Shengliang Guan 已提交
510
static int32_t mndDropUser(SMnode *pMnode, SNodeMsg *pReq, SUserObj *pUser) {
S
Shengliang Guan 已提交
511
  STrans *pTrans = mndTransCreate(pMnode, TRN_POLICY_ROLLBACK, TRN_TYPE_DROP_USER, &pReq->rpcMsg);
S
Shengliang Guan 已提交
512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535
  if (pTrans == NULL) {
    mError("user:%s, failed to drop since %s", pUser->user, terrstr());
    return -1;
  }
  mDebug("trans:%d, used to drop user:%s", pTrans->id, pUser->user);

  SSdbRaw *pRedoRaw = mndUserActionEncode(pUser);
  if (pRedoRaw == NULL || mndTransAppendRedolog(pTrans, pRedoRaw) != 0) {
    mError("trans:%d, failed to append redo log since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }
  sdbSetRawStatus(pRedoRaw, SDB_STATUS_DROPPED);

  if (mndTransPrepare(pMnode, pTrans) != 0) {
    mError("trans:%d, failed to prepare since %s", pTrans->id, terrstr());
    mndTransDrop(pTrans);
    return -1;
  }

  mndTransDrop(pTrans);
  return 0;
}

S
Shengliang Guan 已提交
536 537
static int32_t mndProcessDropUserReq(SNodeMsg *pReq) {
  SMnode      *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
538 539 540 541 542
  int32_t      code = -1;
  SUserObj    *pUser = NULL;
  SUserObj    *pOperUser = NULL;
  SDropUserReq dropReq = {0};

S
Shengliang Guan 已提交
543 544
  if (tDeserializeSDropUserReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &dropReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
545
    goto _OVER;
S
Shengliang Guan 已提交
546
  }
S
Shengliang Guan 已提交
547

S
Shengliang Guan 已提交
548
  mDebug("user:%s, start to drop", dropReq.user);
S
Shengliang Guan 已提交
549

S
Shengliang Guan 已提交
550
  if (dropReq.user[0] == 0) {
S
Shengliang Guan 已提交
551
    terrno = TSDB_CODE_MND_INVALID_USER_FORMAT;
552
    goto _OVER;
S
Shengliang Guan 已提交
553 554
  }

S
Shengliang Guan 已提交
555
  pUser = mndAcquireUser(pMnode, dropReq.user);
S
Shengliang Guan 已提交
556 557
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
558
    goto _OVER;
S
Shengliang Guan 已提交
559 560
  }

S
Shengliang Guan 已提交
561
  pOperUser = mndAcquireUser(pMnode, pReq->user);
S
Shengliang Guan 已提交
562 563
  if (pOperUser == NULL) {
    terrno = TSDB_CODE_MND_NO_USER_FROM_CONN;
564
    goto _OVER;
S
Shengliang Guan 已提交
565 566
  }

S
Shengliang Guan 已提交
567
  if (mndCheckDropUserAuth(pOperUser) != 0) {
568
    goto _OVER;
S
Shengliang Guan 已提交
569 570
  }

S
Shengliang Guan 已提交
571 572
  code = mndDropUser(pMnode, pReq, pUser);
  if (code == 0) code = TSDB_CODE_MND_ACTION_IN_PROGRESS;
S
Shengliang Guan 已提交
573

574
_OVER:
S
Shengliang Guan 已提交
575 576
  if (code != 0 && code != TSDB_CODE_MND_ACTION_IN_PROGRESS) {
    mError("user:%s, failed to drop since %s", dropReq.user, terrstr());
S
Shengliang Guan 已提交
577 578
  }

S
Shengliang Guan 已提交
579 580 581 582
  mndReleaseUser(pMnode, pOperUser);
  mndReleaseUser(pMnode, pUser);

  return code;
S
Shengliang Guan 已提交
583 584
}

D
dapan 已提交
585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614
static int32_t mndSetUserAuthRsp(SMnode       *pMnode, SUserObj *pUser, SGetUserAuthRsp *pRsp) {
  memcpy(pRsp->user, pUser->user, TSDB_USER_LEN);
  pRsp->superAuth = pUser->superUser;
  pRsp->version = pUser->authVersion;
  pRsp->readDbs = mndDupDbHash(pUser->readDbs);
  pRsp->writeDbs = mndDupDbHash(pUser->writeDbs);
  pRsp->createdDbs = taosHashInit(4, taosGetDefaultHashFunction(TSDB_DATA_TYPE_BINARY), true, HASH_NO_LOCK);
  if (NULL == pRsp->createdDbs) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return -1;
  }
  
  SSdb *pSdb = pMnode->pSdb;
  void *pIter = NULL;
  while (1) {
    SDbObj *pDb = NULL;
    pIter = sdbFetch(pSdb, SDB_DB, pIter, (void **)&pDb);
    if (pIter == NULL) break;

    if (strcmp(pDb->createUser, pUser->user) == 0) {
      int32_t len = strlen(pDb->name) + 1;
      taosHashPut(pRsp->createdDbs, pDb->name, len, pDb->name, len);
    }

    sdbRelease(pSdb, pDb);
  }

  return 0;
}

S
Shengliang Guan 已提交
615 616
static int32_t mndProcessGetUserAuthReq(SNodeMsg *pReq) {
  SMnode         *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
617 618 619 620 621
  int32_t         code = -1;
  SUserObj       *pUser = NULL;
  SGetUserAuthReq authReq = {0};
  SGetUserAuthRsp authRsp = {0};

S
Shengliang Guan 已提交
622 623
  if (tDeserializeSGetUserAuthReq(pReq->rpcMsg.pCont, pReq->rpcMsg.contLen, &authReq) != 0) {
    terrno = TSDB_CODE_INVALID_MSG;
624
    goto _OVER;
S
Shengliang Guan 已提交
625
  }
S
Shengliang Guan 已提交
626 627 628 629 630 631

  mTrace("user:%s, start to get auth", authReq.user);

  pUser = mndAcquireUser(pMnode, authReq.user);
  if (pUser == NULL) {
    terrno = TSDB_CODE_MND_USER_NOT_EXIST;
632
    goto _OVER;
S
Shengliang Guan 已提交
633 634
  }

D
dapan 已提交
635 636 637
  code = mndSetUserAuthRsp(pMnode, pUser, &authRsp);
  if (code) {
    goto _OVER;
S
Shengliang Guan 已提交
638 639
  }

S
Shengliang Guan 已提交
640
  int32_t contLen = tSerializeSGetUserAuthRsp(NULL, 0, &authRsp);
S
Shengliang Guan 已提交
641 642 643
  void   *pRsp = rpcMallocCont(contLen);
  if (pRsp == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
644
    goto _OVER;
S
Shengliang Guan 已提交
645 646
  }

S
Shengliang Guan 已提交
647
  tSerializeSGetUserAuthRsp(pRsp, contLen, &authRsp);
S
Shengliang Guan 已提交
648

S
Shengliang Guan 已提交
649 650
  pReq->pRsp = pRsp;
  pReq->rspLen = contLen;
S
Shengliang Guan 已提交
651 652
  code = 0;

653
_OVER:
D
dapan 已提交
654
  
S
Shengliang Guan 已提交
655
  mndReleaseUser(pMnode, pUser);
S
Shengliang Guan 已提交
656
  tFreeSGetUserAuthRsp(&authRsp);
S
Shengliang Guan 已提交
657 658 659 660

  return code;
}

661
static int32_t mndRetrieveUsers(SNodeMsg *pReq, SShowObj *pShow, SSDataBlock *pBlock, int32_t rows) {
S
Shengliang Guan 已提交
662
  SMnode   *pMnode = pReq->pNode;
S
Shengliang Guan 已提交
663 664 665 666 667 668 669 670 671 672 673
  SSdb     *pSdb = pMnode->pSdb;
  int32_t   numOfRows = 0;
  SUserObj *pUser = NULL;
  int32_t   cols = 0;
  char     *pWrite;

  while (numOfRows < rows) {
    pShow->pIter = sdbFetch(pSdb, SDB_USER, pShow->pIter, (void **)&pUser);
    if (pShow->pIter == NULL) break;

    cols = 0;
674
    SColumnInfoData *pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
675 676

    char name[TSDB_USER_LEN + VARSTR_HEADER_SIZE] = {0};
677
    STR_WITH_MAXSIZE_TO_VARSTR(name, pUser->user, pShow->pMeta->pSchemas[cols].bytes);
678

679
    colDataAppend(pColInfo, numOfRows, (const char *)name, false);
680

wafwerar's avatar
wafwerar 已提交
681 682
    cols++;
    pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
683

684 685
    const char *src = pUser->superUser ? "super" : "normal";
    char        b[10 + VARSTR_HEADER_SIZE] = {0};
686
    STR_WITH_SIZE_TO_VARSTR(b, src, strlen(src));
687
    colDataAppend(pColInfo, numOfRows, (const char *)b, false);
688

wafwerar's avatar
wafwerar 已提交
689 690
    cols++;
    pColInfo = taosArrayGet(pBlock->pDataBlock, cols);
691
    colDataAppend(pColInfo, numOfRows, (const char *)&pUser->createdTime, false);
S
Shengliang Guan 已提交
692 693 694 695 696

    numOfRows++;
    sdbRelease(pSdb, pUser);
  }

697
  pShow->numOfRows += numOfRows;
S
Shengliang Guan 已提交
698 699 700 701 702 703
  return numOfRows;
}

static void mndCancelGetNextUser(SMnode *pMnode, void *pIter) {
  SSdb *pSdb = pMnode->pSdb;
  sdbCancelFetch(pSdb, pIter);
S
Shengliang Guan 已提交
704
}
D
dapan 已提交
705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773

int32_t mndValidateUserAuthInfo(SMnode *pMnode, SUserAuthVersion *pUsers, int32_t numOfUses, void **ppRsp, int32_t *pRspLen) {
  SUserAuthBatchRsp batchRsp = {0};
  batchRsp.pArray = taosArrayInit(numOfUses, sizeof(SGetUserAuthRsp));
  if (batchRsp.pArray == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    return -1;
  }

  int32_t code = 0;
  for (int32_t i = 0; i < numOfUses; ++i) {
    SUserObj *pUser = mndAcquireUser(pMnode, pUsers[i].user);
    if (pUser == NULL) {
      mError("user:%s, failed to auth user since %s", pUsers[i].user, terrstr());
      continue;
    }

    if (pUser->authVersion <= pUsers[i].version) {
      mndReleaseUser(pMnode, pUser);
      continue;
    }
    
    SGetUserAuthRsp rsp = {0};
    code = mndSetUserAuthRsp(pMnode, pUser, &rsp);
    if (code) {
      mndReleaseUser(pMnode, pUser);
      tFreeSGetUserAuthRsp(&rsp);
      goto _OVER;
    }


    taosArrayPush(batchRsp.pArray, &rsp);
    mndReleaseUser(pMnode, pUser);
  }

  if (taosArrayGetSize(batchRsp.pArray) <= 0) {
    *ppRsp = NULL;
    *pRspLen = 0;
    
    tFreeSUserAuthBatchRsp(&batchRsp);
    return 0;
  }

  int32_t rspLen = tSerializeSUserAuthBatchRsp(NULL, 0, &batchRsp);
  void   *pRsp = taosMemoryMalloc(rspLen);
  if (pRsp == NULL) {
    terrno = TSDB_CODE_OUT_OF_MEMORY;
    tFreeSUserAuthBatchRsp(&batchRsp);
    return -1;
  }
  tSerializeSUserAuthBatchRsp(pRsp, rspLen, &batchRsp);

  *ppRsp = pRsp;
  *pRspLen = rspLen;

  tFreeSUserAuthBatchRsp(&batchRsp);
  return 0;

_OVER:

  *ppRsp = NULL;
  *pRspLen = 0;
  
  tFreeSUserAuthBatchRsp(&batchRsp);
  return code;
}