CREATE ROUTINE Privilege
This page is part of MariaDB's Documentation.
The parent of this page is: Privileges for MariaDB Xpand
Topics on this page:
Overview
Grants ability to execute CREATE FUNCTION
and CREATE PROCEDURE
.
DETAILS
Scope: Global, Database, Routine
Privilege name for
GRANT
:CREATE ROUTINE
Privilege name for
REVOKE
:CREATE ROUTINE
Privilege shown by
SHOW GRANTS
:CREATE ROUTINE
MariaDB Xpand's CREATE ROUTINE
privilege allows certain SQL statements to be executed:
EXAMPLES
GRANT
The following examples demonstrate grant of a single privilege. A single GRANT
statement can grant multiple privileges at the same scope by providing a comma-separated list of the privileges.
To grant the CREATE ROUTINE
privilege at global scope, replace the user specification ('USERNAME'@'HOSTNAME'
) in the following query to align to your requirements:
GRANT CREATE ROUTINE
ON *.*
TO 'USERNAME'@'HOSTNAME';
To grant the CREATE ROUTINE
privilege at database scope, replace the user specification ('USERNAME'@'HOSTNAME'
) and database name (DATABASE_NAME
) in the following query to align to your requirements:
GRANT CREATE ROUTINE
ON DATABASE_NAME.*
TO 'USERNAME'@'HOSTNAME';
To grant the CREATE ROUTINE
privilege at routine scope, replace the user specification ('USERNAME'@'HOSTNAME'
), database name (DATABASE_NAME
), and routine name (ROUTINE_NAME
) in the following query to align to your requirements:
GRANT CREATE ROUTINE
ON DATABASE_NAME.ROUTINE_NAME
TO 'USERNAME'@'HOSTNAME';
REVOKE
The following examples demonstrate revoke of a single previously-granted privilege. A single REVOKE
statement can revoke multiple privileges at the same scope by providing a comma-separated list of the privileges.
To revoke the CREATE ROUTINE
privilege at global scope, replace the user specification ('USERNAME'@'HOSTNAME'
) in the following query to align to your requirements:
REVOKE CREATE ROUTINE
ON *.*
FROM 'USERNAME'@'HOSTNAME';
To revoke the CREATE ROUTINE
privilege at database scope, replace the user specification ('USERNAME'@'HOSTNAME'
) and database name (DATABASE_NAME
) in the following query to align to your requirements:
REVOKE CREATE ROUTINE
ON DATABASE_NAME.*
FROM 'USERNAME'@'HOSTNAME';
To revoke the CREATE ROUTINE
privilege at routine scope, replace the user specification ('USERNAME'@'HOSTNAME'
), database name (DATABASE_NAME
), and routine name (ROUTINE_NAME
) in the following query to align to your requirements:
REVOKE CREATE ROUTINE
ON DATABASE_NAME.ROUTINE_NAME
FROM 'USERNAME'@'HOSTNAME';
SHOW Output
A user's privileges can be displayed using the SHOW GRANTS
statement.
If the CREATE ROUTINE
privilege is present, it will be shown as CREATE ROUTINE
in the output. For example:
SHOW GRANTS FOR 'app_user'@'192.0.2.%';
+--------------------------------------------------------------+
| Grants for app_user@192.0.2.% |
+--------------------------------------------------------------+
| GRANT CREATE ROUTINE ON `app_db`.* TO 'app_user'@'192.0.2.%' |
+--------------------------------------------------------------+
Privilege Failure
An error message is raised if an operation fails due to insufficient privileges. For example:
CREATE DATABASE db1;
DELIMITER //
CREATE FUNCTION db1.test_func ()
RETURNS INT DETERMINISTIC
BEGIN
RETURN 1;
END//
DELIMITER ;
ERROR 1045 (HY000): [11281] Permission denied: User 'USERNAME'@'HOSTNAME' is missing CREATE ROUTINE on `db1`.*; transaction aborted