Merge pull request #29057 from taosdata/docs/TD-33031-3.0

docs: description of user privileges
This commit is contained in:
Shengliang Guan 2024-12-06 17:44:22 +08:00 committed by GitHub
commit 6f202ef776
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
4 changed files with 16 additions and 6 deletions

View File

@ -12,7 +12,7 @@ TDengine is configured by default with only one root user, who has the highest p
Only the root user can perform the operation of creating users, with the syntax as follows. Only the root user can perform the operation of creating users, with the syntax as follows.
```sql ```sql
create user user_name pass'password' [sysinfo {1|0}] create user user_name pass'password' [sysinfo {1|0}] [createdb {1|0}]
``` ```
The parameters are explained as follows. The parameters are explained as follows.
@ -20,6 +20,7 @@ The parameters are explained as follows.
- user_name: Up to 23 B long. - user_name: Up to 23 B long.
- password: Up to 128 B long, valid characters include letters and numbers as well as special characters other than single and double quotes, apostrophes, backslashes, and spaces, and it cannot be empty. - password: Up to 128 B long, valid characters include letters and numbers as well as special characters other than single and double quotes, apostrophes, backslashes, and spaces, and it cannot be empty.
- sysinfo: Whether the user can view system information. 1 means they can view it, 0 means they cannot. System information includes server configuration information, various node information such as dnode, query node (qnode), etc., as well as storage-related information, etc. The default is to view system information. - sysinfo: Whether the user can view system information. 1 means they can view it, 0 means they cannot. System information includes server configuration information, various node information such as dnode, query node (qnode), etc., as well as storage-related information, etc. The default is to view system information.
- createdb: Whether the user can create databases. 1 means they can create databases, 0 means they cannot. The default value is 0. // Supported starting from TDengine Enterprise version 3.3.2.0
The following SQL can create a user named test with the password 123456 who can view system information. The following SQL can create a user named test with the password 123456 who can view system information.
@ -51,6 +52,7 @@ alter_user_clause: {
pass 'literal' pass 'literal'
| enable value | enable value
| sysinfo value | sysinfo value
| createdb value
} }
``` ```
@ -59,6 +61,7 @@ The parameters are explained as follows.
- pass: Modify the user's password. - pass: Modify the user's password.
- enable: Whether to enable the user. 1 means to enable this user, 0 means to disable this user. - enable: Whether to enable the user. 1 means to enable this user, 0 means to disable this user.
- sysinfo: Whether the user can view system information. 1 means they can view system information, 0 means they cannot. - sysinfo: Whether the user can view system information. 1 means they can view system information, 0 means they cannot.
- createdb: Whether the user can create databases. 1 means they can create databases, 0 means they cannot. // Supported starting from TDengine Enterprise version 3.3.2.0
The following SQL disables the user test. The following SQL disables the user test.

View File

@ -8,7 +8,7 @@ User and permission management is a feature of TDengine Enterprise Edition. This
## Create User ## Create User
```sql ```sql
CREATE USER user_name PASS 'password' [SYSINFO {1|0}]; CREATE USER user_name PASS 'password' [SYSINFO {1|0}] [CREATEDB {1|0}];
``` ```
The username can be up to 23 bytes long. The username can be up to 23 bytes long.
@ -17,6 +17,8 @@ The password can be up to 31 bytes long. The password can include letters, numbe
`SYSINFO` indicates whether the user can view system information. `1` means they can view, `0` means they have no permission to view. System information includes service configuration, dnode, vnode, storage, etc. The default value is `1`. `SYSINFO` indicates whether the user can view system information. `1` means they can view, `0` means they have no permission to view. System information includes service configuration, dnode, vnode, storage, etc. The default value is `1`.
`CREATEDB` indicates whether the user can create databases. `1` means they can create databases, `0` means they have no permission to create databases. The default value is `0`. // Supported starting from TDengine Enterprise version 3.3.2.0
In the example below, we create a user with the password `123456` who can view system information. In the example below, we create a user with the password `123456` who can view system information.
```sql ```sql
@ -76,7 +78,7 @@ alter_user_clause: {
- PASS: Change the password, followed by the new password - PASS: Change the password, followed by the new password
- ENABLE: Enable or disable the user, `1` means enable, `0` means disable - ENABLE: Enable or disable the user, `1` means enable, `0` means disable
- SYSINFO: Allow or prohibit viewing system information, `1` means allow, `0` means prohibit - SYSINFO: Allow or prohibit viewing system information, `1` means allow, `0` means prohibit
- CREATEDB: Allow or prohibit creating databases, `1` means allow, `0` means prohibit - CREATEDB: Allow or prohibit creating databases, `1` means allow, `0` means prohibit. // Supported starting from TDengine Enterprise version 3.3.2.0
The following example disables the user named `test`: The following example disables the user named `test`:

View File

@ -12,13 +12,14 @@ TDengine 默认仅配置了一个 root 用户该用户拥有最高权限。TD
创建用户的操作只能由 root 用户进行,语法如下。 创建用户的操作只能由 root 用户进行,语法如下。
```sql ```sql
create user user_name pass'password' [sysinfo {1|0}] create user user_name pass'password' [sysinfo {1|0}] [createdb {1|0}]
``` ```
相关参数说明如下。 相关参数说明如下。
- user_name最长为 23 B。 - user_name最长为 23 B。
- password最长为 128 B合法字符包括字母和数字以及单双引号、撇号、反斜杠和空格以外的特殊字符且不可以为空。 - password最长为 128 B合法字符包括字母和数字以及单双引号、撇号、反斜杠和空格以外的特殊字符且不可以为空。
- sysinfo 用户是否可以查看系统信息。1 表示可以查看0 表示不可以查看。系统信息包括服务端配置信息、服务端各种节点信息,如 dnode、查询节点qnode以及与存储相关的信息等。默认为可以查看系统信息。 - sysinfo 用户是否可以查看系统信息。1 表示可以查看0 表示不可以查看。系统信息包括服务端配置信息、服务端各种节点信息,如 dnode、查询节点qnode以及与存储相关的信息等。默认为可以查看系统信息。
- createdb用户是否可以创建数据库。1 表示可以创建0 表示不可以创建。缺省值为 0。// 从 TDengine 企业版 3.3.2.0 开始支持
如下 SQL 可以创建密码为 123456 且可以查看系统信息的用户 test。 如下 SQL 可以创建密码为 123456 且可以查看系统信息的用户 test。
@ -47,6 +48,7 @@ alter_user_clause: {
pass 'literal' pass 'literal'
| enable value | enable value
| sysinfo value | sysinfo value
| createdb value
} }
``` ```
@ -54,6 +56,7 @@ alter_user_clause: {
- pass修改用户密码。 - pass修改用户密码。
- enable是否启用用户。1 表示启用此用户0 表示禁用此用户。 - enable是否启用用户。1 表示启用此用户0 表示禁用此用户。
- sysinfo 用户是否可查看系统信息。1 表示可以查看系统信息0 表示不可以查看系统信息 - sysinfo 用户是否可查看系统信息。1 表示可以查看系统信息0 表示不可以查看系统信息
- createdb用户是否可创建数据库。1 表示可以创建数据库0 表示不可以创建数据库。// 从 TDengine 企业版 3.3.2.0 开始支持
如下 SQL 禁用 test 用户。 如下 SQL 禁用 test 用户。
```sql ```sql

View File

@ -9,7 +9,7 @@ description: 本节讲述基本的用户管理功能
## 创建用户 ## 创建用户
```sql ```sql
CREATE USER user_name PASS 'password' [SYSINFO {1|0}]; CREATE USER user_name PASS 'password' [SYSINFO {1|0}] [CREATEDB {1|0}];
``` ```
用户名最长不超过 23 个字节。 用户名最长不超过 23 个字节。
@ -18,6 +18,8 @@ CREATE USER user_name PASS 'password' [SYSINFO {1|0}];
`SYSINFO` 表示该用户是否能够查看系统信息。`1` 表示可以查看,`0` 表示无权查看。系统信息包括服务配置、dnode、vnode、存储等信息。缺省值为 `1` `SYSINFO` 表示该用户是否能够查看系统信息。`1` 表示可以查看,`0` 表示无权查看。系统信息包括服务配置、dnode、vnode、存储等信息。缺省值为 `1`
`CREATEDB` 表示该用户是否能够创建数据库。`1` 表示可以创建,`0` 表示无权创建。缺省值为 `0`。// 从 TDengine 企业版 3.3.2.0 开始支持
在下面的示例中,我们创建一个密码为 `123456` 且可以查看系统信息的用户。 在下面的示例中,我们创建一个密码为 `123456` 且可以查看系统信息的用户。
```sql ```sql
@ -77,7 +79,7 @@ alter_user_clause: {
- PASS: 修改密码,后跟新密码 - PASS: 修改密码,后跟新密码
- ENABLE: 启用或禁用该用户,`1` 表示启用,`0` 表示禁用 - ENABLE: 启用或禁用该用户,`1` 表示启用,`0` 表示禁用
- SYSINFO: 允许或禁止查看系统信息,`1` 表示允许,`0` 表示禁止 - SYSINFO: 允许或禁止查看系统信息,`1` 表示允许,`0` 表示禁止
- CREATEDB: 允许或禁止创建数据库,`1` 表示允许,`0` 表示禁止 - CREATEDB: 允许或禁止创建数据库,`1` 表示允许,`0` 表示禁止。// 从 TDengine 企业版 3.3.2.0 开始支持
下面的示例禁用了名为 `test` 的用户: 下面的示例禁用了名为 `test` 的用户: