5. 建立使用者、授權以及修改密碼等許可權操作

純愛楓若情發表於2018-01-30

今天突然有了修改密碼的需求,然後試著在網上搜了下方法,好像都不能成功,後來看了下官方文件才發現,是因為我用的mysql版本太高了,已經改變了修改密碼的方法。

檢視mysql版本

如果還沒連線到mysql伺服器,那麼採用以下三種方法:

-- 方法一
C:\Users\root>mysql -V
mysql  Ver 14.14 Distrib 5.7.20, for Win64 (x86_64)

-- 方法二
C:\Users\root>mysql --help | find "Distrib"
mysql  Ver 14.14 Distrib 5.7.20, for Win64 (x86_64)

-- 方法三,可以看到登入的時候會顯示mysql版本資訊
C:\Users\root>mysql -uroot -p
Enter password: *******
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 20
Server version: 5.7.20-log MySQL Community Server (GPL)

Copyright (c) 2000, 2017, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

如果已經連線到mysql資料庫,採用以下三種方法:

-- 第一種方法
mysql> select version();
+------------+
| version()  |
+------------+
| 5.7.20-log |
+------------+
1 row in set (0.00 sec)

-- 第二種方法
mysql> status
--------------
mysql  Ver 14.14 Distrib 5.7.20, for Win64 (x86_64)

Connection id:          21
Current database:
Current user:           root@localhost
SSL:                    Not in use
Using delimiter:        ;
Server version:         5.7.20-log MySQL Community Server (GPL)
Protocol version:       10
Connection:             localhost via TCP/IP
Server characterset:    utf8
Db     characterset:    utf8
Client characterset:    gbk
Conn.  characterset:    gbk
TCP port:               3306
Uptime:                 6 days 46 min 10 sec

Threads: 1  Questions: 158  Slow queries: 0  Opens: 135  Flush tables: 1  Open tables: 125 Queries per second avg: 0.000
--------------

-- 第三種方法
mysql> \s
--------------
mysql  Ver 14.14 Distrib 5.7.20, for Win64 (x86_64)

Connection id:          21
Current database:
Current user:           root@localhost
SSL:                    Not in use
Using delimiter:        ;
Server version:         5.7.20-log MySQL Community Server (GPL)
Protocol version:       10
Connection:             localhost via TCP/IP
Server characterset:    utf8
Db     characterset:    utf8
Client characterset:    gbk
Conn.  characterset:    gbk
TCP port:               3306
Uptime:                 6 days 48 min 28 sec

Threads: 1  Questions: 161  Slow queries: 0  Opens: 135  Flush tables: 1  Open tables: 125 Queries per second avg: 0.000
--------------

總結

因此,由以上檢視版本的方法,可以知道,我用的mysql版本為5.7.20-log MySQL Community Server (GPL),已經不支援以前修改密碼的方式了。

檢視系統配置

-- 資料庫系統配置儲存在mysql資料庫中,切換到mysql資料庫
mysql> show databases;
+--------------------+
| Database           |
+--------------------+
| information_schema |
| menageries         |
| mysql              |
| performance_schema |
| sakila             |
| sys                |
| test               |
| world              |
+--------------------+
8 rows in set (0.00 sec)

mysql> use mysql
Database changed

-- 可以看出,使用者配置資訊儲存在user表中
mysql> show tables;
+---------------------------+
| Tables_in_mysql           |
+---------------------------+
| columns_priv              |
| db                        |
| engine_cost               |
| event                     |
| func                      |
| general_log               |
| gtid_executed             |
| help_category             |
| help_keyword              |
| help_relation             |
| help_topic                |
| innodb_index_stats        |
| innodb_table_stats        |
| ndb_binlog_index          |
| plugin                    |
| proc                      |
| procs_priv                |
| proxies_priv              |
| server_cost               |
| servers                   |
| slave_master_info         |
| slave_relay_log_info      |
| slave_worker_info         |
| slow_log                  |
| tables_priv               |
| time_zone                 |
| time_zone_leap_second     |
| time_zone_name            |
| time_zone_transition      |
| time_zone_transition_type |
| user                      |
+---------------------------+
31 rows in set (0.27 sec)

-- 檢視錶格屬性有哪些,由於表格太長,此處不一一列出,分析知道其中有一行名為authentication_string,這就是我們找的屬性
mysql> describe user;
……
 authentication_string  | text
……

-- 果然這裡面儲存的是使用者密碼,但是並非明文顯示
mysql> select  user,authentication_string from user;
+---------------+-------------------------------------------+
| user          | authentication_string                     |
+---------------+-------------------------------------------+
| root          | *FAAFFE644E901CFAFAEC7562415E5FAEC243B8B2 |
| mysql.session | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| mysql.sys     | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| test          | *676243218923905CF94CB52A3C9D3EB30CE8E20D |
+---------------+-------------------------------------------+
4 rows in set (0.00 sec)

建立使用者

mysql> create user '2b'@'localhost' identified by '2b';
Query OK, 0 rows affected (1.06 sec)

mysql> select  user,authentication_string from user;
+---------------+-------------------------------------------+
| user          | authentication_string                     |
+---------------+-------------------------------------------+
| root          | *FAAFFE644E901CFAFAEC7562415E5FAEC243B8B2 |
| mysql.session | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| mysql.sys     | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| test          | *676243218923905CF94CB52A3C9D3EB30CE8E20D |
| 2b            | *3382AC02521A1462D80B82F33C8F09029CD69A42 |
+---------------+-------------------------------------------+
5 rows in set (0.00 sec)

可以看到,我們成功的建立了一個使用者2b,我們給他設定了密碼2b,但是是加密顯示的。

刪除使用者

mysql> delete from user where user='2b';
Query OK, 1 row affected (0.45 sec)

mysql> select  user,authentication_string from user;
+---------------+-------------------------------------------+
| user          | authentication_string                     |
+---------------+-------------------------------------------+
| root          | *FAAFFE644E901CFAFAEC7562415E5FAEC243B8B2 |
| mysql.session | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| mysql.sys     | *THISISNOTAVALIDPASSWORDTHATCANBEUSEDHERE |
| test          | *676243218923905CF94CB52A3C9D3EB30CE8E20D |
+---------------+-------------------------------------------+
4 rows in set (0.00 sec)

執行刪除命令的時候,千萬要再三確認再回車,不然誤刪了就麻煩了。

授權

mysql> grant all on test.* to 'test'@'localhost';
Query OK, 0 rows affected (0.05 sec)

命令:grant privileges on databasename.tablename to ‘username’@’host’

privileges為使用者操作許可權,如select、insert等,如果要授予所有的許可權,則用all;
databasename為資料庫名,table那麼為相對應的資料庫中的列表,如果授予全部列表,則用星號表示。

檢視使用者授權

使用show grants for user@host命令檢視

mysql> show grants for test@localhost;
+--------------------------------------------------------+
| Grants for test@localhost                              |
+--------------------------------------------------------+
| GRANT USAGE ON *.* TO 'test'@'localhost'               |
| GRANT ALL PRIVILEGES ON `test`.* TO 'test'@'localhost' |
+--------------------------------------------------------+
2 rows in set (0.00 sec)

撤銷使用者許可權

使用REVOKE命令來收回分配出去的許可權。

mysql> revoke all on test.* from 'test'@'localhost';
Query OK, 0 rows affected (0.00 sec)

flush privileges

建立了使用者,刪除了使用者,進行了授權以後,儘量進行flush privileges;操作,否則可能相應的操作並不能立即生效。

更改使用者密碼

我又實驗了一下,用之前的版本的修改方法修改密碼:

-- 看起來好像不成功
mysql> set password for '2b'@'localhost'=password('123');
Query OK, 0 rows affected, 1 warning (0.03 sec)

當我執行完上面命令以後,提示我有一個警示,沒有資料受到影響。但是當我用123這個密碼登陸2b使用者的時候,竟然登上去了!!!這騙得我太辛苦了……^;^

然後我又換了一種方法,用新加的authentication_string屬性去修改密碼,居然也成功了!

mysql> update mysql.user set authentication_string=password('123') where user='2b';
Query OK, 1 row affected, 1 warning (0.08 sec)
Rows matched: 1  Changed: 1  Warnings: 1

-- 下面這一行必須要執行,否則不能立即生效
mysql> flush privileges;
Query OK, 0 rows affected (0.03 sec)

但是從這第二種方法明顯可以看出,修改成功了,因為它顯示一行受到影響。

相關文章