1
0

init.sql 3.3 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. -- ---------------------------------------------------------
  2. -- Initial Database and User Setup (Run as MySQL Root)
  3. -- ---------------------------------------------------------
  4. CREATE DATABASE IF NOT EXISTS food_db CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
  5. -- 1. Create the Owner User
  6. -- Has full rights and can grant privileges to others.
  7. CREATE USER IF NOT EXISTS 'db_owner'@'%' IDENTIFIED BY 'owner_pass';
  8. GRANT ALL PRIVILEGES ON food_db.* TO 'db_owner'@'%' WITH GRANT OPTION;
  9. -- 2. Create the Reader User
  10. -- Has only connect and read permissions.
  11. CREATE USER IF NOT EXISTS 'db_reader'@'%' IDENTIFIED BY 'reader_pass';
  12. GRANT USAGE ON *.* TO 'db_reader'@'%';
  13. -- 3. Create the Loader User
  14. -- Has connect and data manipulation permissions to load files.
  15. CREATE USER IF NOT EXISTS 'db_loader'@'%' IDENTIFIED BY 'loader_pass';
  16. GRANT USAGE ON *.* TO 'db_loader'@'%';
  17. GRANT FILE ON *.* TO 'db_loader'@'%'; -- Essential for LOAD DATA INFILE from any directory
  18. -- 4. Create the App Auth User
  19. -- Segregation of Duties: Handles only users table for web application routing.
  20. CREATE USER IF NOT EXISTS 'db_app_auth'@'%' IDENTIFIED BY 'app_auth_placeholder_pass';
  21. -- Note: Replace 'app_auth_placeholder_pass' later outside this script.
  22. GRANT USAGE ON *.* TO 'db_app_auth'@'%';
  23. FLUSH PRIVILEGES;
  24. -- ---------------------------------------------------------
  25. -- Table Creation & Grants (Logically executed by db_owner)
  26. -- ---------------------------------------------------------
  27. USE food_db;
  28. -- NOTE: The syntax you provided (`read_csv_auto`) is specific to DuckDB!
  29. -- MySQL does NOT support `read_csv_auto()` to dynamically create tables from CSV.
  30. -- In MySQL, you MUST define the table schema first, and then use LOAD DATA INFILE.
  31. -- Here is the MySQL equivalent process:
  32. -- Step A.1: Create Web Users Table
  33. CREATE TABLE IF NOT EXISTS users (
  34. id INT AUTO_INCREMENT PRIMARY KEY,
  35. username VARCHAR(100) UNIQUE NOT NULL,
  36. password_hash VARCHAR(255) NOT NULL,
  37. created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
  38. ) ENGINE=InnoDB;
  39. GRANT SELECT, INSERT, UPDATE ON food_db.users TO 'db_app_auth'@'%';
  40. FLUSH PRIVILEGES;
  41. -- Step A.2: Create the table with known columns (Example structure for OpenFoodFacts)
  42. CREATE TABLE IF NOT EXISTS products (
  43. code VARCHAR(50) PRIMARY KEY,
  44. url TEXT,
  45. creator VARCHAR(255),
  46. created_t VARCHAR(50),
  47. created_datetime VARCHAR(50),
  48. last_modified_t VARCHAR(50),
  49. last_modified_datetime VARCHAR(50),
  50. product_name TEXT,
  51. generic_name TEXT,
  52. quantity VARCHAR(255),
  53. packaging TEXT,
  54. brands TEXT,
  55. categories TEXT,
  56. origins TEXT,
  57. labels TEXT,
  58. stores TEXT,
  59. countries TEXT,
  60. ingredients_text TEXT,
  61. allergens TEXT,
  62. traces TEXT,
  63. -- Add FULLTEXT index for context search on ingredients and products
  64. FULLTEXT INDEX ft_idx_search (product_name, ingredients_text)
  65. ) ENGINE=InnoDB;
  66. -- Step B: The Owner grants explicit privileges to the Reader and Loader
  67. GRANT SELECT ON food_db.products TO 'db_reader'@'%';
  68. GRANT SELECT, INSERT, UPDATE, DELETE, DROP, CREATE ON food_db.products TO 'db_loader'@'%';
  69. FLUSH PRIVILEGES;
  70. -- Step C: The Loader user would then run this MySQL command to import:
  71. /*
  72. LOAD DATA INFILE '/path/to/en.openfoodfacts.org.products.converted.csv'
  73. INTO TABLE products
  74. FIELDS TERMINATED BY '\t'
  75. ENCLOSED BY ''
  76. LINES TERMINATED BY '\n'
  77. IGNORE 1 ROWS;
  78. */