Updated on 2024-04-18 GMT+08:00

Modifying Database Object Permissions

Function

This API is used to modify database object permissions.

Call Method

For details, see Calling APIs.

URI

POST /v1/{project_id}/clusters/{cluster_id}/db-manager/authority
Table 1 URI parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Project ID. For details about how to obtain the ID, see Obtaining Project ID.

cluster_id

Yes

String

Cluster ID. For details about how to obtain the ID, see Obtaining the Cluster ID.

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

type

Yes

String

Object type [DATABASE | SCHEMA | TABLE | VIEW | COLUMN | FUNCTION| SEQUENCE | NODEGROUP | ROLE].

is_grant

Yes

Boolean

Whether to grant a permission

grant_list

No

Array of Grant objects

This parameter is mandatory when is_grant is set to true.

revoke_list

No

Array of Revoke objects

List of revoked permissions. This parameter is mandatory when is_grant is set to false.

role_list

Yes

Array of strings

List of roles that a permission is granted

object_list

Yes

Array of strings

List of objects to which a permission belongs

all_object

No

Boolean

Permissions on all database objects in a schema. The default value is false.

cascade

No

Boolean

Whether a permission is revoked in cascading mode. The default value is true.

Default value: true

database

Yes

String

Database name

schema

No

String

Schema name

table

No

String

Table name

Table 3 Grant

Parameter

Mandatory

Type

Description

permission

Yes

String

Permission name. The permission varies depending on the database object type.

  • database CREATE | CONNECT | TEMPORARY | TEMP ALL PRIVILEGES

  • schema CREATE | USAGE | ALTER | DROP ALL PRIVILEGES

  • table SELECT | INSERT | UPDATE | DELETE | TRUNCATE | REFERENCES | TRIGGER | ANALYZE | ANALYSE | VACUUM | ALTER | DROP ALL PRIVILEGES

  • view SELECT | INSERT | UPDATE | DELETE | TRUNCATE | REFERENCES | TRIGGER | ANALYZE | ANALYSE | VACUUM | ALTER | DROP ALL PRIVILEGES

  • column SELECT | INSERT | UPDATE | REFERENCES ALL PRIVILEGES

  • function EXECUTE ALL PRIVILEGES

  • sequence SELECT | UPDATE | USAGE ALL PRIVILEGES

  • nodegroup CREATE | USAGE | COMPUTE ALL PRIVILEGES

  • role role_name (role name)

grant_with

Yes

Boolean

Whether a permission is included in the grant options.

Table 4 Revoke

Parameter

Mandatory

Type

Description

permission

Yes

String

Permission name. The permission varies depending on the database object type.

  • database CREATE | CONNECT | TEMPORARY | TEMP ALL PRIVILEGES

  • schema CREATE | USAGE | ALTER | DROP ALL PRIVILEGES

  • table SELECT | INSERT | UPDATE | DELETE | TRUNCATE | REFERENCES | TRIGGER | ANALYZE | ANALYSE | VACUUM | ALTER | DROP ALL PRIVILEGES

  • view SELECT | INSERT | UPDATE | DELETE | TRUNCATE | REFERENCES | TRIGGER | ANALYZE | ANALYSE | VACUUM | ALTER | DROP ALL PRIVILEGES

  • column SELECT | INSERT | UPDATE | REFERENCES ALL PRIVILEGES

  • function EXECUTE ALL PRIVILEGES

  • sequence SELECT | UPDATE | USAGE ALL PRIVILEGES

  • nodegroup CREATE | USAGE | COMPUTE ALL PRIVILEGES

  • role role_name (role name)

revoke_with

Yes

Boolean

Whether to remove a grant option.

Response Parameters

Status code: 200

Table 5 Response body parameter

Parameter

Type

Description

view_sql

Array of strings

SQL list.

Example Request

Modify the database object permission of the cluster whose ID is a89aea88-7ea2-40bd-8ac8-8b93e169e5d6. Specifically, grant the SELECT permission of table1 and table2 in a GaussDB database to user1 and user2 in the schema public.

POST https://{Endpoint}/v1/0536cdee2200d5912f7cc00b877980f1/clusters/a89aea88-7ea2-40bd-8ac8-8b93e169e5d6/db-manager/authority

{
  "type" : "table",
  "is_grant" : true,
  "grant_list" : [ {
    "permission" : "SELECT",
    "grant_with" : true
  } ],
  "role_list" : [ "user1", "user2" ],
  "object_list" : [ "table1", "table2" ],
  "database" : "gaussdb",
  "schema" : "public"
}

Example Response

Status code: 200

User information details

{
  "view_sql" : [ "GRANT SELECT ON TABLE public.test_t1 TO user1 WITH GRANT OPTION;", "GRANT UPDATE ON TABLE public.test_t1 TO user1 ;" ]
}

SDK Sample Code

The sample code is as follows:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.dws.v2.region.DwsRegion;
import com.huaweicloud.sdk.dws.v2.*;
import com.huaweicloud.sdk.dws.v2.model.*;

import java.util.List;
import java.util.ArrayList;

public class UpdateDatabaseAuthoritySolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");

        ICredential auth = new BasicCredentials()
                .withAk(ak)
                .withSk(sk);

        DwsClient client = DwsClient.newBuilder()
                .withCredential(auth)
                .withRegion(DwsRegion.valueOf("cn-north-4"))
                .build();
        UpdateDatabaseAuthorityRequest request = new UpdateDatabaseAuthorityRequest();
        DatabasePermissionReq body = new DatabasePermissionReq();
        List<String> listbodyRoleList = new ArrayList<>();
        listbodyRoleList.add("user1");
        listbodyRoleList.add("user2");
        List<Grant> listbodyGrantList = new ArrayList<>();
        listbodyGrantList.add(
            new Grant()
                .withPermission("SELECT")
                .withGrantWith(true)
        );
        body.withSchema("public");
        body.withDatabase("gaussdb");
        body.withObjectList("[table1, table2]");
        body.withRoleList(listbodyRoleList);
        body.withGrantList(listbodyGrantList);
        body.withIsGrant(true);
        body.withType("table");
        request.withBody(body);
        try {
            UpdateDatabaseAuthorityResponse response = client.updateDatabaseAuthority(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
# coding: utf-8

from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkdws.v2.region.dws_region import DwsRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkdws.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.getenv("CLOUD_SDK_AK")
    sk = os.getenv("CLOUD_SDK_SK")

    credentials = BasicCredentials(ak, sk) \

    client = DwsClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(DwsRegion.value_of("cn-north-4")) \
        .build()

    try:
        request = UpdateDatabaseAuthorityRequest()
        listRoleListbody = [
            "user1",
            "user2"
        ]
        listGrantListbody = [
            Grant(
                permission="SELECT",
                grant_with=True
            )
        ]
        request.body = DatabasePermissionReq(
            schema="public",
            database="gaussdb",
            object_list="[table1, table2]",
            role_list=listRoleListbody,
            grant_list=listGrantListbody,
            is_grant=True,
            type="table"
        )
        response = client.update_database_authority(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    dws "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")

    auth := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        Build()

    client := dws.NewDwsClient(
        dws.DwsClientBuilder().
            WithRegion(region.ValueOf("cn-north-4")).
            WithCredential(auth).
            Build())

    request := &model.UpdateDatabaseAuthorityRequest{}
	var listRoleListbody = []string{
        "user1",
	    "user2",
    }
	var listGrantListbody = []model.Grant{
        {
            Permission: "SELECT",
            GrantWith: true,
        },
    }
	schemaDatabasePermissionReq:= "public"
	request.Body = &model.DatabasePermissionReq{
		Schema: &schemaDatabasePermissionReq,
		Database: "gaussdb",
		ObjectList: "[table1, table2]",
		RoleList: listRoleListbody,
		GrantList: &listGrantListbody,
		IsGrant: true,
		Type: "table",
	}
	response, err := client.UpdateDatabaseAuthority(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For more SDK sample codes of programming languages, visit API Explorer and click the Sample Code tab. Example codes can be automatically generated.

Status Code

Status Code

Description

200

User information details

400

Request error.

401

Authentication failed.

403

You do not have required permissions.

404

No resources found.

500

Internal server error.

503

The service was unavailable.