fix(rbac): forbiden grant create-ownership-object privilege to user #18987
+143
−94
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I hereby agree to the terms of the CLA available at: https://docs.databend.com/dev/policies/cla/
Summary
Old flow was as simple as GRANT CREATE ON default. * TO USER b; and CREATE TABLE t AS ...; which implicitly set the owner to public. Now the tests at tests/suites/0_stateless/18_rbac/18_0007_privilege_access.sh:239-258 show the
enforced pattern:
In pr
If b reverts to SET ROLE public the final CREATE is rejected, so there is no chance to create a table owned by public.
Tests
Type of change
This change is