CreateTableMustHaveOneGrant

CreateTableMustHaveOneGrant is a custom policy check that requires every CREATE TABLE statement to also have at least one GRANT included.

regex: (?is)(?=.*\b(create\s+table)\b)(?!.*\b(grant)\b).*

This example utilizes Oracle. You can use this check as it is or customize it further to fit your needs in your SQL database. All Regex Custom Policy Checks can only run against the changelog, not against the database.

Scope Database
changelog Oracle

Step-by-Step

Note: These steps describe how to create the custom policy check. It does not exist by default in Liquibase Pro.

  1. Enter this command into the CLI: 
    liquibase checks customize --check-name=SqlUserDefinedPatternCheck
  2. Give your check a short name for easier identification. In this example we will title the check:
    CreateTableMustHaveOneGrant
  3. Set the Severity to return a code of 0-4 when triggered.
    Options: 'INFO'=0, 'MINOR'=1, 'MAJOR'=2, 'CRITICAL'=3, 'BLOCKER'=4

  4. Set the SEARCH_STRING to this valid regular expression:
    (?is)(?=.*\b(create\s+table)\b)(?!.*\b(grant)\b).*

  5. Set the MESSAGE for when a match for regular expression <SEARCH_STRING> is found in a Changeset:

    Example: Error! CREATE TABLE statement found but there was no GRANT found. Every CREATE TABLE must have at least one GRANT statement.

  6. Set STRIP_COMMENTS to true if you want to remove the comments from the output.

  7. Leave the PATH_Filter_REGEX blank.

  8. Set 'SPLIT_STATEMENTS' to false so Liquibase does not split multiple SQL statements on the delimiter or evaluate each individually.
    The regex custom policy check is created successfully.

Sample Passing Script

Copy
--changeset amalik:employee
CREATE TABLE EMPLOYEE (
   EMPLOYEE_ID INT NOT NULL GENERATED ALWAYS AS IDENTITY    CONSTRAINT PEOPLE_PK PRIMARY KEY, 
   FIRST_NAME VARCHAR(26),
   LAST_NAME VARCHAR(26)
);
GRANT select ON EMPLOYEE to APPUSER;

Sample Failing Scripts

Copy
--changeset amalik:employee
CREATE TABLE EMPLOYEE (
   EMPLOYEE_ID INT NOT NULL GENERATED ALWAYS AS IDENTITY    CONSTRAINT PEOPLE_PK, 
   FIRST_NAME VARCHAR(26),
   LAST_NAME VARCHAR(26)
);

Sample Error Message

Copy
CHANGELOG CHECKS
----------------
Checks completed validation of the changelog and found the following issues:

Check Name:         Check for specific patterns in sql (CreateTableMustHaveOneGrant)
Changeset ID:       EMPLOYEE
Changeset Filepath: script1.sql
Check Severity:     MAJOR (Return code: 2)
Message:            Error! CREATE TABLE statement found but there was no GRANT found. Every CREATE TABLE must have at least one GRANT statement.