deephaven_enterprise.edge_acl

This module supports the creation of access control lists (ACLs) for the results of Persistent Queries. For more information on ACLs and filter generators, see the Deephaven documentation https://deephaven.io/enterprise/docs/sys-admin/permissions/acls/#persistent-query-acls.

Module Contents

class EdgeAclProvider(j_provider)[source]

An EdgeAclProvider is used to provide access control for the results of Persistent Queries based on the requesting user at request time.

Note that it should not be instantiated directly, but rather through the EdgeAclProviderBuilder.build() method.

Parameters:

j_provider (jpy.JType)

static add_full_access(value)[source]

Adds visibility for the specified object to all users and groups.

Parameters:

value (Union[jpy.JType, Any]) – the object to add visibility for

Return type:

None

static add_object_acl(group, value)[source]

Adds visibility for the specified object to the specified group.

Parameters:
  • group (str) – the group to add visibility for

  • value (Union[jpy.JType, Any]) – the object to add visibility for

Return type:

None

static apply_full_access(table)[source]

Applies a full-access (“allusers”) Edge ACL to the given table.

This is a convenience for building a provider with a single full-access row ACL for the allusers group and applying it:

EdgeAclProvider.builder().row_acl("allusers", acl_generator.full_access()).build().apply_to(table)

The resulting table is not transformed for any user, but is marked as ACL-bearing so that it may be exported once ACLs have been applied somewhere in the query.

Parameters:

table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable

Returns:

a new table with a full-access ACL attached

Return type:

TableType

static apply_full_access_for_current_user(table)[source]

Applies a full-access Edge ACL for the current user to the given table.

Unlike apply_full_access(), which grants access to the allusers group, this grants full access only to the user in the current authorization context (a user is always a member of a group named for themselves). Use it to mark a result computed in a viewer’s context as exportable to that viewer alone. The caller is responsible for ensuring the data is already sanitized for that user.

Parameters:

table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable

Returns:

a new table with a current-user full-access ACL attached

Return type:

TableType

apply_to(table)[source]

Attaches this ACL Provider to a table

Parameters:

table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable

Returns:

a new table with the ACLs attached

Return type:

TableType

static builder()[source]

Creates a builder to construct an EdgeAclProvider

Returns:

EdgeAclProviderBuilder

Return type:

EdgeAclProviderBuilder

class EdgeAclProviderBuilder(j_builder)[source]

Bases: deephaven._wrapper.JObjectWrapper

A builder for constructing an EdgeAclProvider for access control on the result tables of Persistent Queries.

Note that it should not be instantiated directly, but rather through the static EdgeAclProvider.builder().

Parameters:

j_builder (_JEdgeAclProviderBuilder)

build()[source]

Constructs the completed EdgeAclProvider object from the current state of this builder.

Returns:

EdgeAclProvider

Return type:

EdgeAclProvider

column_acl(group, columns, acl)[source]

Adds a Column ACL for the specified group and column(s) to the table with a filter generator. The filter generator is created by calling one of the factory functions in acl_generator. The Column ACL controls access to specific values of columns of a table.

Parameters:
  • group (str) – the group the ACL applies to

  • columns (Union[str, list[str]]) – the column(s) the acl applies to

  • acl (JAclFilterGenerator) – the generator that will produce a filter for a given user

Returns:

self

Return type:

EdgeAclProviderBuilder

orphan_promotion(promote_orphans)[source]

Specify whether orphans should be promoted after applying this ACL to a tree table. Defaults to False and is ignored on other types of tables.

Parameters:

promote_orphans (bool) – whether orphans should be promoted after applying this ACL

Returns:

this builder

row_acl(group, acl)[source]

Adds a Row ACL for the specified group to the table with a filter generator. The filter generator is created by calling one of the factory functions in acl_generator. The Row Acl controls access to rows of a table.

Parameters:
  • group (str) – the group the ACL applies to

  • acl (JAclFilterGenerator) – the generator that will produce a filter for a given user

Returns:

self

Return type:

EdgeAclProviderBuilder