You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
admin_readonly is a built‑in role created at startup. It grants global read privileges (SELECT + SHOW VIEW) and is registered by the role manager.
SU is implemented as a command that switches the current session user and sets an explicit role override list. It requires the current user to be root; otherwise it throws.
Role resolution flow
When privileges are checked, the system builds a PrivilegeContext for the current session. If currentRoles is set on the session and the current user matches, that set is used for role resolution; otherwise the user’s default roles are used.
Role resolution can also include LDAP roles when LDAP auth is enabled.
How admin_readonly affects behavior
If the resolved role set contains admin_readonly, some “read‑only admin” shortcuts kick in:
SHOW RESOURCES is allowed.
SHOW WORKLOAD GROUP is allowed.
Process list visibility is expanded (both local and RPC paths check for admin_readonly).
How SU interacts with admin_readonly
SU sets currentRoles explicitly. If admin_readonly is in that list (or comes from LDAP/local roles depending on resolution rules), the session gains the read‑only admin behaviors above.
If SU specifies no roles, the current code falls back to the target user’s local roles (and then merges LDAP roles). So “no roles” does not mean “no privileges” by default.
Issue Number: close #xxx
Related PR: #xxx
Problem Summary:
Release note
None
Check List (For Author)
Test
Regression test
Unit Test
Manual test (add detailed scripts or steps below)
No need to test or manual test. Explain why:
This is a refactor/code format and no logic has been changed.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What problem does this PR solve?
Overview
Role resolution flow
How admin_readonly affects behavior
How SU interacts with admin_readonly
Issue Number: close #xxx
Related PR: #xxx
Problem Summary:
Release note
None
Check List (For Author)
Test
Behavior changed:
Does this need documentation?
Check List (For Reviewer who merge this PR)