|
1 | 1 | #!/usr/bin/env sh |
2 | 2 |
|
| 3 | +set -eu |
| 4 | + |
| 5 | +# shellcheck disable=SC3040 |
| 6 | +if (set -o pipefail 2>/dev/null); then |
| 7 | + set -o pipefail |
| 8 | +fi |
| 9 | + |
| 10 | +log() { |
| 11 | + printf '[sql-grant] %s\n' "${1}" |
| 12 | +} |
| 13 | + |
3 | 14 | if ! [ -x "$(command -v mysql)" ]; then |
4 | | - echo "Error: the mysql client is not installed or is not in your path. Please add the mysql client executable." >&2 |
| 15 | + log "Error: the mysql client is not installed or is not in your path. Please add the mysql client executable." >&2 |
5 | 16 | exit 1 |
6 | 17 | elif ! [ -x "$(command -v nc)" ]; then |
7 | | - echo "Error: Netcat is not installed." >&2 |
| 18 | + log "Error: Netcat is not installed." >&2 |
8 | 19 | exit 1 |
9 | 20 | fi |
10 | 21 |
|
11 | 22 | for j in $(seq 1 10); do |
12 | 23 | READY=$(sh -c 'nc -v ${CLOUDSQL_PROXY_HOST} ${CLOUDSQL_PROXY_PORT} </dev/null; echo $?;' 2>/dev/null) |
13 | 24 |
|
14 | 25 | if [ "$READY" -eq 0 ]; then |
15 | | - echo "Connection with with CloudSQL Auth Proxy established at ${CLOUDSQL_PROXY_HOST}." |
| 26 | + log "Connection with CloudSQL Auth Proxy established at ${CLOUDSQL_PROXY_HOST}:${CLOUDSQL_PROXY_PORT}." |
16 | 27 | break |
17 | 28 | fi |
18 | | - echo "Waiting for Cloud SQL Proxy to start... $j" |
| 29 | + log "Waiting for Cloud SQL Proxy to start (attempt ${j}/10)..." |
19 | 30 | sleep 1s |
20 | 31 | done |
21 | 32 |
|
22 | 33 | if [ "$READY" -eq 0 ]; then |
23 | | - if [ "${MYSQL_VERSION:0:9}" = "MYSQL_5_7" ]; then |
24 | | - mysql --host=${CLOUDSQL_PROXY_HOST} --port=${CLOUDSQL_PROXY_PORT} --user=${CLOUDSQL_PRIVILEGED_USER_NAME} --password=${CLOUDSQL_PRIVILEGED_USER_PASSWORD} --execute="REVOKE ALL PRIVILEGES, GRANT OPTION FROM '${USER}'@'${USER_HOST}'; GRANT ALL ON ${DATABASE}.* TO ${USER}@'${USER_HOST}';" |
25 | | - fi |
| 34 | + USER_IDENTIFIER="'${USER}'@'${USER_HOST}'" |
| 35 | + DATABASE_IDENTIFIER="\`${DATABASE}\`.*" |
26 | 36 |
|
27 | | - if [ "${MYSQL_VERSION:0:9}" = "MYSQL_8_0" ]; then |
28 | | - mysql --host=${CLOUDSQL_PROXY_HOST} --port=${CLOUDSQL_PROXY_PORT} --user=${CLOUDSQL_PRIVILEGED_USER_NAME} --password=${CLOUDSQL_PRIVILEGED_USER_PASSWORD} --execute="REVOKE cloudsqlsuperuser FROM '${USER}'@'${USER_HOST}'; GRANT ALL ON ${DATABASE}.* TO ${USER}@'${USER_HOST}';" |
| 37 | + log "Preparing privilege statements for ${USER_IDENTIFIER} on database \`${DATABASE}\` (MySQL ${MYSQL_VERSION})." |
| 38 | + |
| 39 | + case "${MYSQL_VERSION}" in |
| 40 | + MYSQL_5_7*) |
| 41 | + SQL_COMMANDS="REVOKE ALL PRIVILEGES, GRANT OPTION FROM ${USER_IDENTIFIER}; GRANT ALL PRIVILEGES ON ${DATABASE_IDENTIFIER} TO ${USER_IDENTIFIER};" |
| 42 | + ;; |
| 43 | + MYSQL_8_0*|MYSQL_8_4*) |
| 44 | + SQL_COMMANDS="REVOKE cloudsqlsuperuser FROM ${USER_IDENTIFIER}; SET DEFAULT ROLE NONE TO ${USER_IDENTIFIER}; GRANT ALL PRIVILEGES ON ${DATABASE_IDENTIFIER} TO ${USER_IDENTIFIER};" |
| 45 | + ;; |
| 46 | + *) |
| 47 | + log "ERROR: Unsupported MySQL version ${MYSQL_VERSION}." >&2 |
| 48 | + exit 1 |
| 49 | + ;; |
| 50 | + esac |
| 51 | + |
| 52 | + printf '[sql-grant] Executing SQL statements:\n%s\n' "${SQL_COMMANDS}" |
| 53 | + |
| 54 | + if ! mysql --host="${CLOUDSQL_PROXY_HOST}" --port="${CLOUDSQL_PROXY_PORT}" --user="${CLOUDSQL_PRIVILEGED_USER_NAME}" --password="${CLOUDSQL_PRIVILEGED_USER_PASSWORD}" --execute="${SQL_COMMANDS}"; then |
| 55 | + log "ERROR: Failed to apply privileges for ${USER_IDENTIFIER} on ${DATABASE}." >&2 |
| 56 | + exit 1 |
29 | 57 | fi |
30 | 58 |
|
| 59 | + log "Successfully applied privileges for ${USER_IDENTIFIER}." |
| 60 | + |
31 | 61 | exit 0 |
32 | 62 | else |
33 | | - echo "ERROR: cannot connect to the CloudSQL Auth Proxy at ${CLOUDSQL_PROXY_HOST}, please check your settings." |
| 63 | + log "ERROR: cannot connect to the CloudSQL Auth Proxy at ${CLOUDSQL_PROXY_HOST}:${CLOUDSQL_PROXY_PORT}, please check your settings." >&2 |
34 | 64 | exit 1 |
35 | 65 | fi |
0 commit comments