CalvinKirs opened a new pull request, #68559:
URL: https://github.com/apache/doris/pull/68559

   ### What problem does this PR solve?
   
   Issue Number: None
   
   Related PR: #50904
   
   Problem Summary:
   
   #50904 made only `root@'%'` and `admin@'%'` system users 
(`UserIdentity.isRootUser()` / `isSystemUser()` compare the full identity), so 
`CREATE USER 'root'@'8.8.20.39'` is allowed and creates an ordinary account, 
and `DROP USER` drops it. `SET PASSWORD` and `ALTER USER` were not updated and 
still decide "is this root" from the user name alone, ignoring the host:
   
   ```sql
   CREATE USER 'root'@'8.8.20.39' IDENTIFIED BY 'Pwd_a1';
   SET PASSWORD FOR 'root'@'8.8.20.39' = PASSWORD('Pwd_b2');
   -- ERROR: Can not set password for root user, except root itself
   ```
   
   - `SetPassVarOp` refuses every target named `root` other than the current 
user itself, so nobody, `root@'%'` included, can set the password of 
`root@'8.8.20.39'`.
   - `AlterUserInfo` refuses `ACCOUNT_LOCK` on every account named `root` ("Can 
not lock root user"), and compares both the target and the current user by name 
for "Only root user can modify root user", so a GRANT user can not `ALTER USER 
'root'@'8.8.20.39'`, and every account named `root` counts as `root@'%'` there.
   
   This PR uses `UserIdentity.isRootUser()` in these checks, for the target 
and, in `AlterUserInfo`, for the current user as well, the predicate `CREATE 
USER` and `DROP USER` already use (`SetPassVarOp` already compares the full 
identity for "root itself"). `root@'<host>'` is now managed like any other 
account by a user with GRANT privilege, while `root@'%'` can still only be 
modified by `root@'%'` itself and still can not be locked.
   
   ### Release note
   
   `SET PASSWORD` and `ALTER USER` now treat only `root@'%'` as the root user. 
An account created as `root@'<host>'` can have its password changed, and be 
altered or locked, by a user with GRANT privilege like any other account.
   
   ### Check List (For Author)
   
   - Test <!-- At least one of them must be included. -->
       - [x] Regression test
       - [x] Unit Test
       - [x] Manual test (add detailed scripts or steps below)
       - [ ] No need to test or manual test. Explain why:
           - [ ] This is a refactor/code format and no logic has been changed.
           - [ ] Previous test can cover this change.
           - [ ] No code files have been changed.
           - [ ] Other reason <!-- Add your reason?  -->
   
       - FE UT: new `SystemRootUserTest` and 
`AccountLockTest#testRootAtSpecificHostCanBeLocked`, both failing without the 
fix; `SetPasswordTest`, `AlterUserStmtTest`, `AlterUserCommandTest`, 
`SetPasswordParseTest`, `EncryptSQLTest`, `AuthTest` still pass.
       - Regression: `account_p0/test_system_user` (extended), plus 
`test_root_user`, `test_set_password`, `test_account_lock`, `test_alter_user`, 
on a local FE built from this branch.
       - Manual: the statements above, then `ALTER USER 'root'@'8.8.20.39' 
ACCOUNT_LOCK / ACCOUNT_UNLOCK` and `DROP USER 'root'@'8.8.20.39'`, all succeed; 
`ALTER USER 'root'@'%' ACCOUNT_LOCK` is still rejected.
   
   - Behavior changed:
       - [ ] No.
       - [x] Yes. <!-- Explain the behavior change -->
         `root@'<host>'` accounts are ordinary accounts for `SET PASSWORD` / 
`ALTER USER`; only `root@'%'` itself can modify `root@'%'`.
   
   - Does this need documentation?
       - [x] No.
       - [ ] Yes. <!-- Add document PR link here. eg: 
https://github.com/apache/doris-website/pull/1214 -->
   
   ### Check List (For Reviewer who merge this PR)
   
   - [ ] Confirm the release note
   - [ ] Confirm test cases
   - [ ] Confirm document
   - [ ] Add branch pick label <!-- Add branch pick label that this PR should 
merge into -->
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to