MySQL re-granting
[hcoop/domtool2.git] / src / plugins / domtool-mysql
dissimilarity index 64%
index d2c5298..5d67086 100755 (executable)
@@ -1,51 +1,62 @@
-#!/bin/sh -e
-
-case $1 in
-       adduser)
-               USERNAME=$2
-               PASSWORD=$3
-
-               kinit -k -t /etc/keytabs/root.admin.keytab root/admin
-               aklog
-
-               if ! vos examine db.$USERNAME >/dev/null 2>/dev/null; then
-                       vos create -server afs -partition a -name db.$USERNAME -maxquota 5000
-                       fs mkmount -dir /afs/.hcoop.net/common/.databases/$USERNAME -vol db.$USERNAME -rw
-                       fs setacl -dir /afs/hcoop.net/common/databases/$USERNAME -acl databases l
-                       fs setacl -dir /afs/hcoop.net/common/databases/$USERNAME -acl system:backup rl
-               fi
-
-               sudo -H mysql -e "CREATE USER '$USERNAME'@'localhost' IDENTIFIED BY '$PASSWORD';"
-       ;;
-       passwd)
-               USERNAME=$2
-               PASSWORD=$3
-
-               sudo -H mysql -e "SET PASSWORD FOR '$USERNAME'@'localhost' = PASSWORD('$PASSWORD');"
-       ;;
-       createdb)
-               USERNAME=$2
-               DBNAME_BASE=$3
-               DBNAME="${USERNAME}_${DBNAME_BASE}"
-               DIR=/afs/hcoop.net/common/databases/$USERNAME/mysql
-
-               kinit -k -t /etc/keytabs/root.admin.keytab root/admin
-               aklog
-
-               mkdir -p $DIR
-               fs setacl -dir $DIR -acl mysql rlid
-               fs setacl -dir $DIR -acl databases none
-               fs setacl -dir $DIR -acl system:backup rl
-               mkdir $DIR/$DBNAME
-               chown mysql:mysql $DIR/$DBNAME
-               chmod 770 $DIR/$DBNAME
-               ln -sf $DIR/$DBNAME /var/lib/mysql/$DBNAME
-               fs setacl -dir $DIR/$DBNAME/ -acl mysql all
-
-               sudo -H mysql -e "GRANT CREATE,SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE VIEW,SHOW VIEW,GRANT OPTION ON TABLE * TO '$USERNAME'@'localhost';" $DBNAME
-               sudo -H mysql -e "FLUSH PRIVILEGES;"
-       ;;
-       *)
-               echo "Usage: domtool-mysql [adduser <user> <password> | passwd <user> <password> | createdb <user> <table>]"
-       ;;
-esac
+#!/bin/bash -e
+
+WHERE="'%.hcoop.net'"
+
+case $1 in
+       adduser)
+               USERNAME=$2
+               PASSWORD=$3
+
+               sudo -H mysql -e "CREATE USER '$USERNAME'@$WHERE IDENTIFIED BY '$PASSWORD';"
+       ;;
+
+       passwd)
+               USERNAME=$2
+               PASSWORD=$3
+
+               sudo -H mysql -e "SET PASSWORD FOR '$USERNAME'@$WHERE = PASSWORD('$PASSWORD');"
+       ;;
+
+       createdb)
+               USERNAME=$2
+               DBNAME_BASE=$3
+               DBNAME="${USERNAME}_${DBNAME_BASE}"
+               DIR=/afs/hcoop.net/common/databases/${USERNAME:0:1}/${USERNAME:0:2}/$USERNAME/mysql
+
+               kinit -k -t /etc/keytabs/root.admin.keytab root/admin
+               aklog
+
+               if [ ! -d $DIR ]; then
+                       echo WARNING: $DIR must already exist!
+               fi
+
+               mkdir $DIR/$DBNAME
+               chown mysql:mysql $DIR/$DBNAME
+               chmod 770 $DIR/$DBNAME
+               ln -sf $DIR/$DBNAME /var/lib/mysql/$DBNAME
+               fs setacl -dir $DIR/$DBNAME/ -acl system:mysql all
+               sudo -H mysql -e "GRANT CREATE,SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE VIEW,SHOW VIEW,LOCK TABLES,GRANT OPTION ON TABLE * TO '$USERNAME'@$WHERE;" $DBNAME
+
+               sudo -H mysql -e "FLUSH PRIVILEGES;"
+       ;;
+
+       dropdb)
+               USERNAME=$2
+               DBNAME_BASE=$3
+               DBNAME="${USERNAME}_${DBNAME_BASE}"
+
+               sudo -H mysql -e "DROP DATABASE $DBNAME;"
+       ;;
+
+       grant)
+               USERNAME=$2
+               DBNAME_BASE=$3
+               DBNAME="${USERNAME}_${DBNAME_BASE}"
+
+               sudo -H mysql -e "GRANT CREATE,SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE VIEW,SHOW VIEW,LOCK TABLES,GRANT OPTION ON TABLE * TO '$USERNAME'@$WHERE;" $DBNAME
+       ;;
+
+       *)
+               echo "Usage: domtool-mysql [adduser <user> <password> | passwd <user> <password> | createdb <user> <db> | dropdb <user> <db> | grant <user> <db>]"
+       ;;
+esac