deephaven_enterprise.edge_acl¶
This module supports the creation of access control lists (ACLs) for the results of Persistent Queries. For more information on ACLs and filter generators, see the Deephaven documentation https://deephaven.io/enterprise/docs/sys-admin/permissions/acls/#persistent-query-acls.
Module Contents¶
- class EdgeAclProvider(j_provider)[source]¶
An EdgeAclProvider is used to provide access control for the results of Persistent Queries based on the requesting user at request time.
Note that it should not be instantiated directly, but rather through the
EdgeAclProviderBuilder.build()method.- Parameters:
j_provider (jpy.JType)
- static add_full_access(value)[source]¶
Adds visibility for the specified object to all users and groups.
- Parameters:
value (Union[jpy.JType, Any]) – the object to add visibility for
- Return type:
None
- static add_object_acl(group, value)[source]¶
Adds visibility for the specified object to the specified group.
- static apply_full_access(table)[source]¶
Applies a full-access (“allusers”) Edge ACL to the given table.
This is a convenience for building a provider with a single full-access row ACL for the
allusersgroup and applying it:EdgeAclProvider.builder().row_acl("allusers", acl_generator.full_access()).build().apply_to(table)
The resulting table is not transformed for any user, but is marked as ACL-bearing so that it may be exported once ACLs have been applied somewhere in the query.
- Parameters:
table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable
- Returns:
a new table with a full-access ACL attached
- Return type:
TableType
- static apply_full_access_for_current_user(table)[source]¶
Applies a full-access Edge ACL for the current user to the given table.
Unlike
apply_full_access(), which grants access to theallusersgroup, this grants full access only to the user in the current authorization context (a user is always a member of a group named for themselves). Use it to mark a result computed in a viewer’s context as exportable to that viewer alone. The caller is responsible for ensuring the data is already sanitized for that user.- Parameters:
table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable
- Returns:
a new table with a current-user full-access ACL attached
- Return type:
TableType
- apply_to(table)[source]¶
Attaches this ACL Provider to a table
- Parameters:
table (TableType) – the object to attach to, must be a Table, RollupTable, TreeTable, PivotTable, or PartitionedTable
- Returns:
a new table with the ACLs attached
- Return type:
TableType
- class EdgeAclProviderBuilder(j_builder)[source]¶
Bases:
deephaven._wrapper.JObjectWrapperA builder for constructing an EdgeAclProvider for access control on the result tables of Persistent Queries.
Note that it should not be instantiated directly, but rather through the static
EdgeAclProvider.builder().- Parameters:
j_builder (_JEdgeAclProviderBuilder)
- build()[source]¶
Constructs the completed
EdgeAclProviderobject from the current state of this builder.- Returns:
EdgeAclProvider
- Return type:
- column_acl(group, columns, acl)[source]¶
Adds a Column ACL for the specified group and column(s) to the table with a filter generator. The filter generator is created by calling one of the factory functions in
acl_generator. The Column ACL controls access to specific values of columns of a table.- Parameters:
- Returns:
self
- Return type:
- orphan_promotion(promote_orphans)[source]¶
Specify whether orphans should be promoted after applying this ACL to a tree table. Defaults to False and is ignored on other types of tables.
- Parameters:
promote_orphans (bool) – whether orphans should be promoted after applying this ACL
- Returns:
this builder
- row_acl(group, acl)[source]¶
Adds a Row ACL for the specified group to the table with a filter generator. The filter generator is created by calling one of the factory functions in
acl_generator. The Row Acl controls access to rows of a table.- Parameters:
group (str) – the group the ACL applies to
acl (JAclFilterGenerator) – the generator that will produce a filter for a given user
- Returns:
self
- Return type: