# Questions about user roles

**URL:** <https://community.cratedb.com/t/questions-about-user-roles/2050>\
**Category:** CrateDB\
**Created:** [July 3, 2025, 9:16am UTC](https://community.cratedb.com/t/questions-about-user-roles/2050 "2025-07-03T09:16:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreas.schneider](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@andreas.schneider](https://community.cratedb.com/u/andreas.schneider)\
**Post date:** [July 3, 2025, 9:16am UTC](https://community.cratedb.com/t/questions-about-user-roles/2050/1 "2025-07-03T09:16:33Z")

</div>

Hello Team,

I have a few questions about user roles.

SET UP  
Empty database (login as user crate)  
Execute the following commands  
CREATE USER admin;  
CREATE USER testUser;  
CREATE ROLE role\_admin;  
CREATE ROLE role\_test;  
Grant AL to role\_admin;  
Grant role\_admin to admin;  
Grant role\_test to testuser;

Login as admin  
Grant role\_test to testuser;  
Grant role\_admin to admin;

Issue 1  
If you execute the command  
SELECT name, granted\_roles, password, superuser FROM sys.users order by name;  
The user testuser has the role role\_test twice.  
Why can a user have the same role twice?  
Is there a way to remove all roles from a user without logging in with all users who have set the roles?

Issue 2  
If the user admin has been deleted, how can the role\_test, which was set by the user admin, be removed from the user testuser?

Issue 3  
Why can the user admin give himself the role\_admin?  
Why can a user give themselves a role?

Can someone answer my questions?  
Thank you for your answers.

---

<div class="post-metadata">

**Author:** ![surister](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/surister/32/1087_2.png) [@surister](https://community.cratedb.com/u/surister)\
**Post date:** [July 3, 2025, 12:12pm UTC](https://community.cratedb.com/t/questions-about-user-roles/2050/2 "2025-07-03T12:12:54Z")

</div>

Hi, thank you for your report!

# Issue 1:

> Why can a user have the same role twice?

I was able to reproduce this, it looks like a bug to me, this only happens if the role is being given by another user, I’ll create an issue with the core team.

> Is there a way to remove all roles from a user without logging in with all users who have set the roles?

No, at least, with the current implementation, if the first issue gets confirmed as a bug and is fixed, I suppose this will not be an issue anymore, otherwise we could raise a feature request to make easier to drop all roles.

## Issue 2

> If the user admin has been deleted, how can the role\_test, which was set by the user admin, be removed from the user testuser?

I think it currently cannot be done, or I can’t find a way to, its a result of the current implementation.

# Issue 3

> Why can the user admin give himself the role\_admin?  
> Why can a user give themselves a role?

The same answer as issue 1-2.

Overall it all seems to stem from the fact that when we grant a role to a user, it seems that we check that tuple (role, grantor) exists within the user instead of just role.

---

<div class="post-metadata">

**Author:** ![surister](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/surister/32/1087_2.png) [@surister](https://community.cratedb.com/u/surister)\
**Post date:** [July 3, 2025, 12:57pm UTC](https://community.cratedb.com/t/questions-about-user-roles/2050/3 "2025-07-03T12:57:29Z")

</div>

I reported the issue, you can follow it here [Same role can be granted twice on a user · Issue #18099 · crate/crate · GitHub](https://github.com/crate/crate/issues/18099)

Thanks again for your report, things like this help us improve!

---

<div class="post-metadata">

**Author:** ![andreas.schneider](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@andreas.schneider](https://community.cratedb.com/u/andreas.schneider)\
**Post date:** [July 3, 2025, 2:11pm UTC](https://community.cratedb.com/t/questions-about-user-roles/2050/4 "2025-07-03T14:11:28Z")

</div>

Thank you for the quick reply.  
I will follow the issue and wait for the solution.

---

<div class="post-metadata">

**Author:** ![surister](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/surister/32/1087_2.png) [@surister](https://community.cratedb.com/u/surister)\
**Post date:** [July 8, 2025, 2:15pm UTC](https://community.cratedb.com/t/questions-about-user-roles/2050/5 "2025-07-08T14:15:04Z")

</div>

Hi there! Just a heads up, the issue was fixed and will most likely be available in the next hotfix release: `5.10.11`. It is planned planned for **2025/07/14** if nothing goes wrong.
