CREATE USER
Создает аккаунты пользователей.
Синт аксис:
CREATE USER [IF NOT EXISTS | OR REPLACE] name1 [, name2 [,...]] [ON CLUSTER cluster_name]
    [NOT IDENTIFIED | IDENTIFIED {[WITH {plaintext_password | sha256_password | sha256_hash | double_sha1_password | double_sha1_hash}] BY {'password' | 'hash'}} | WITH NO_PASSWORD | {WITH ldap SERVER 'server_name'} | {WITH kerberos [REALM 'realm']} | {WITH ssl_certificate CN 'common_name' | SAN 'TYPE:subject_alt_name'} | {WITH ssh_key BY KEY 'public_key' TYPE 'ssh-rsa|...'} | {WITH http SERVER 'server_name' [SCHEME 'Basic']} 
    [, {[{plaintext_password | sha256_password | sha256_hash | ...}] BY {'password' | 'hash'}} | {ldap SERVER 'server_name'} | {...} | ... [,...]]]
    [HOST {LOCAL | NAME 'name' | REGEXP 'name_regexp' | IP 'address' | LIKE 'pattern'} [,...] | ANY | NONE]
    [VALID UNTIL datetime]
    [IN access_storage_type]
    [DEFAULT ROLE role [,...]]
    [DEFAULT DATABASE database | NONE]
    [GRANTEES {user | role | ANY | NONE} [,...] [EXCEPT {user | role} [,...]]]
    [SETTINGS variable [= value] [MIN [=] min_value] [MAX [=] max_value] [READONLY | WRITABLE] | PROFILE 'profile_name'] [,...]
ON CLUSTER позволяет создавать пользователей в кластере, см. Распределенные DDL.
Идентификация
Существует несколько способов идентификации пользователя:
- IDENTIFIED WITH no_password
- IDENTIFIED WITH plaintext_password BY 'qwerty'
- IDENTIFIED WITH sha256_password BY 'qwerty'or- IDENTIFIED BY 'password'
- IDENTIFIED WITH sha256_hash BY 'hash'or- IDENTIFIED WITH sha256_hash BY 'hash' SALT 'salt'
- IDENTIFIED WITH double_sha1_password BY 'qwerty'
- IDENTIFIED WITH double_sha1_hash BY 'hash'
- IDENTIFIED WITH bcrypt_password BY 'qwerty'
- IDENTIFIED WITH bcrypt_hash BY 'hash'
- IDENTIFIED WITH ldap SERVER 'server_name'
- IDENTIFIED WITH kerberosor- IDENTIFIED WITH kerberos REALM 'realm'
- IDENTIFIED WITH ssl_certificate CN 'mysite.com:user'
- IDENTIFIED WITH ssh_key BY KEY 'public_key' TYPE 'ssh-rsa', KEY 'another_public_key' TYPE 'ssh-ed25519'
- IDENTIFIED BY 'qwerty'
Для идентификации с sha256_hash используя SALT - хэш должен быть вычислен от конкатенации 'password' и 'salt'.