MySQL5.7 mysql.user表沒有password字段改 authentication_string;
一. 創(chuàng)建用戶:
- 命令:
CREATE USER 'username'@'host' IDENTIFIED BY 'password';
- 例子:
CREATE USER 'dog'@'localhost' IDENTIFIED BY '123456';
CREATE USER 'dog2'@'localhost' IDENTIFIED BY '';
- PS:username - 你將創(chuàng)建的用戶名,
- host - 指定該用戶在哪個主機(jī)上可以登陸,此處的"localhost",是指該用戶只能在本地登錄,不能在另外一臺機(jī)器上遠(yuǎn)程登錄,如果想遠(yuǎn)程登錄的話,將"localhost"改為"%",表示在任何一臺電腦上都可以登錄;也可以指定某臺機(jī)器可以遠(yuǎn)程登錄;
- password - 該用戶的登陸密碼,密碼可以為空,如果為空則該用戶可以不需要密碼登陸服務(wù)器。
二.授權(quán):
- 命令:
GRANT privileges ON databasename.tablename TO 'username'@'host'
-
PS:
- privileges - 用戶的操作權(quán)限,如SELECT , INSERT , UPDATE 等(詳細(xì)列表見該文最后面).如果要授予所的權(quán)限則使用ALL.;
- databasename - 數(shù)據(jù)庫名,tablename-表名,如果要授予該用戶對所有數(shù)據(jù)庫和表的相應(yīng)操作權(quán)限則可用表示, 如.*.
例子:
GRANT SELECT, INSERT ON mq.* TO 'dog'@'localhost';
三.創(chuàng)建用戶同時授權(quán)
mysql> grant all privileges on mq.* to test@localhost identified by '1234';Query OK, 0 rows affected, 1 warning (0.00 sec)
mysql> flush privileges;Query OK, 0 rows affected (0.01 sec)
- PS:必須執(zhí)行:
**flush privileges; **
**否則登錄時提示:ERROR 1045 (28000): Access denied for user 'user'@'localhost' (using password: YES ) **
四.設(shè)置與更改用戶密碼
命令:SET PASSWORD FOR 'username'@'host' = PASSWORD('newpassword');
例子: SET PASSWORD FOR 'dog2'@'localhost' = PASSWORD("dog");
五.撤銷用戶權(quán)限
- 命令: REVOKE privilege ON databasename.tablename FROM 'username'@'host';
- 說明: privilege, databasename, tablename - 同授權(quán)部分.
- 例子:
REVOKE SELECT ON mq.* FROM 'dog2'@'localhost';
- PS:
假如你在給用戶'dog'@'localhost''授權(quán)的時候是這樣的(或類似的):GRANT SELECT ON test.user TO 'dog'@'localhost', 則在使用REVOKE SELECT ON . FROM 'dog'@'localhost';命令并不能撤銷該用戶對test數(shù)據(jù)庫中user表的SELECT 操作.相反,如果授權(quán)使用的是GRANT SELECT ON . TO 'dog'@'localhost';則REVOKE SELECT ON test.user FROM 'dog'@'localhost';命令也不能撤銷該用戶對test數(shù)據(jù)庫中user表的Select 權(quán)限.
具體信息可以用命令SHOW GRANTS FOR 'dog'@'localhost'; 查看.
六.刪除用戶
- 命令: DROP USER 'username'@'host';
七.查看用戶的授權(quán)
mysql> show grants for dog@localhost;+---------------------------------------------+| Grants for dog@localhost |+---------------------------------------------+| GRANT USAGE ON *.* TO 'dog'@'localhost' || GRANT INSERT ON `mq`.* TO 'dog'@'localhost' |+---------------------------------------------+2 rows in set (0.00 sec)
- PS:
GRANT USAGE:mysql usage權(quán)限就是空權(quán)限,默認(rèn)create user的權(quán)限,只能連庫,啥也不能干**