Modifying Database Object Permissions
Function
This API is used to modify database object permissions.
Call Method
For details, see Calling APIs.
URI
POST /v1/{project_id}/clusters/{cluster_id}/db-manager/authority
Parameter |
Mandatory |
Type |
Description |
---|---|---|---|
project_id |
Yes |
String |
Project ID. For details about how to obtain the ID, see Obtaining Project ID. |
cluster_id |
Yes |
String |
Cluster ID. For details about how to obtain the ID, see Obtaining the Cluster ID. |
Request Parameters
Parameter |
Mandatory |
Type |
Description |
---|---|---|---|
type |
Yes |
String |
Object type [DATABASE | SCHEMA | TABLE | VIEW | COLUMN | FUNCTION| SEQUENCE | NODEGROUP | ROLE]. |
is_grant |
Yes |
Boolean |
Whether to grant a permission |
grant_list |
No |
Array of Grant objects |
This parameter is mandatory when is_grant is set to true. |
revoke_list |
No |
Array of Revoke objects |
List of revoked permissions. This parameter is mandatory when is_grant is set to false. |
role_list |
Yes |
Array of strings |
List of roles that a permission is granted |
object_list |
Yes |
Array of strings |
List of objects to which a permission belongs |
all_object |
No |
Boolean |
Permissions on all database objects in a schema. The default value is false. |
cascade |
No |
Boolean |
Whether a permission is revoked in cascading mode. The default value is true. Default value: true |
database |
Yes |
String |
Database name |
schema |
No |
String |
Schema name |
table |
No |
String |
Table name |
Parameter |
Mandatory |
Type |
Description |
---|---|---|---|
permission |
Yes |
String |
Permission name. The permission varies depending on the database object type. |
grant_with |
Yes |
Boolean |
Whether a permission is included in the grant options. |
Parameter |
Mandatory |
Type |
Description |
---|---|---|---|
permission |
Yes |
String |
Permission name. The permission varies depending on the database object type. |
revoke_with |
Yes |
Boolean |
Whether to remove a grant option. |
Response Parameters
Status code: 200
Parameter |
Type |
Description |
---|---|---|
view_sql |
Array of strings |
SQL list. |
Example Request
Modify the database object permission of the cluster whose ID is a89aea88-7ea2-40bd-8ac8-8b93e169e5d6. Specifically, grant the SELECT permission of table1 and table2 in a GaussDB database to user1 and user2 in the schema public.
POST https://{Endpoint}/v1/0536cdee2200d5912f7cc00b877980f1/clusters/a89aea88-7ea2-40bd-8ac8-8b93e169e5d6/db-manager/authority { "type" : "table", "is_grant" : true, "grant_list" : [ { "permission" : "SELECT", "grant_with" : true } ], "role_list" : [ "user1", "user2" ], "object_list" : [ "table1", "table2" ], "database" : "gaussdb", "schema" : "public" }
Example Response
Status code: 200
User information details
{ "view_sql" : [ "GRANT SELECT ON TABLE public.test_t1 TO user1 WITH GRANT OPTION;", "GRANT UPDATE ON TABLE public.test_t1 TO user1 ;" ] }
SDK Sample Code
The sample code is as follows:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 |
package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.dws.v2.region.DwsRegion; import com.huaweicloud.sdk.dws.v2.*; import com.huaweicloud.sdk.dws.v2.model.*; import java.util.List; import java.util.ArrayList; public class UpdateDatabaseAuthoritySolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); ICredential auth = new BasicCredentials() .withAk(ak) .withSk(sk); DwsClient client = DwsClient.newBuilder() .withCredential(auth) .withRegion(DwsRegion.valueOf("cn-north-4")) .build(); UpdateDatabaseAuthorityRequest request = new UpdateDatabaseAuthorityRequest(); DatabasePermissionReq body = new DatabasePermissionReq(); List<String> listbodyRoleList = new ArrayList<>(); listbodyRoleList.add("user1"); listbodyRoleList.add("user2"); List<Grant> listbodyGrantList = new ArrayList<>(); listbodyGrantList.add( new Grant() .withPermission("SELECT") .withGrantWith(true) ); body.withSchema("public"); body.withDatabase("gaussdb"); body.withObjectList("[table1, table2]"); body.withRoleList(listbodyRoleList); body.withGrantList(listbodyGrantList); body.withIsGrant(true); body.withType("table"); request.withBody(body); try { UpdateDatabaseAuthorityResponse response = client.updateDatabaseAuthority(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 |
# coding: utf-8 from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkdws.v2.region.dws_region import DwsRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkdws.v2 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.getenv("CLOUD_SDK_AK") sk = os.getenv("CLOUD_SDK_SK") credentials = BasicCredentials(ak, sk) \ client = DwsClient.new_builder() \ .with_credentials(credentials) \ .with_region(DwsRegion.value_of("cn-north-4")) \ .build() try: request = UpdateDatabaseAuthorityRequest() listRoleListbody = [ "user1", "user2" ] listGrantListbody = [ Grant( permission="SELECT", grant_with=True ) ] request.body = DatabasePermissionReq( schema="public", database="gaussdb", object_list="[table1, table2]", role_list=listRoleListbody, grant_list=listGrantListbody, is_grant=True, type="table" ) response = client.update_database_authority(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 |
package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" dws "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dws/v2/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") auth := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). Build() client := dws.NewDwsClient( dws.DwsClientBuilder(). WithRegion(region.ValueOf("cn-north-4")). WithCredential(auth). Build()) request := &model.UpdateDatabaseAuthorityRequest{} var listRoleListbody = []string{ "user1", "user2", } var listGrantListbody = []model.Grant{ { Permission: "SELECT", GrantWith: true, }, } schemaDatabasePermissionReq:= "public" request.Body = &model.DatabasePermissionReq{ Schema: &schemaDatabasePermissionReq, Database: "gaussdb", ObjectList: "[table1, table2]", RoleList: listRoleListbody, GrantList: &listGrantListbody, IsGrant: true, Type: "table", } response, err := client.UpdateDatabaseAuthority(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
For more SDK sample codes of programming languages, visit API Explorer and click the Sample Code tab. Example codes can be automatically generated.
Status Code
Status Code |
Description |
---|---|
200 |
User information details |
400 |
Request error. |
401 |
Authentication failed. |
403 |
You do not have required permissions. |
404 |
No resources found. |
500 |
Internal server error. |
503 |
The service was unavailable. |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot