-
Notifications
You must be signed in to change notification settings - Fork 2k
feat(bigquery): Add cloud-client samples for access policies #3975
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 4 commits
5925b0f
e24c2e8
84ec0f6
21f786e
5d408c7
62e343a
c87d659
58ee72a
62ebc2c
9d0ce88
627536a
70cfb83
ff35988
b8ad0f4
7b38e5a
5cfa8dc
ccf30d6
eb32aa8
0a5f5dd
6c40940
b600729
c7a1821
db956a7
b013b3c
3f3d68a
12bc84b
b9e4bb1
e6e886f
ec3c990
232b73b
7c45228
f6a685d
dbb3a4d
5c04884
eed264a
20609bf
f721a80
158f0b0
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| // Copyright 2025 Google LLC | ||
| // | ||
| // Licensed under the Apache License, Version 2.0 (the "License"); | ||
| // you may not use this file except in compliance with the License. | ||
| // You may obtain a copy of the License at | ||
| // | ||
| // http://www.apache.org/licenses/LICENSE-2.0 | ||
| // | ||
| // Unless required by applicable law or agreed to in writing, software | ||
| // distributed under the License is distributed on an "AS IS" BASIS, | ||
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| // See the License for the specific language governing permissions and | ||
| // limitations under the License. | ||
|
|
||
| "use strict"; | ||
|
Check failure on line 15 in bigquery/cloud-client/app.js
|
||
|
|
||
| const { viewDatasetAccessPolicy } = require("./src/viewDatasetAccessPolicy") | ||
|
Check failure on line 17 in bigquery/cloud-client/app.js
|
||
| const { viewTableOrViewAccessPolicy } = require("./src/viewTableOrViewAccessPolicy") | ||
|
Check failure on line 18 in bigquery/cloud-client/app.js
|
||
|
|
||
| async function main() { | ||
| try { | ||
| // Example usage of dataset access policy viewer | ||
| await viewDatasetAccessPolicy(); | ||
|
|
||
| // Example usage of table/view access policy viewer | ||
| const projectId = process.env.GOOGLE_CLOUD_PROJECT; | ||
| await viewTableOrViewAccessPolicy({ | ||
| projectId, | ||
| datasetId: "my_new_dataset", | ||
| resourceName: "my_table", | ||
| }); | ||
| } catch (error) { | ||
| console.error("Error:", error); | ||
| processors.exitCode = 1; | ||
| } | ||
| } | ||
|
Check failure on line 36 in bigquery/cloud-client/app.js
|
||
|
|
||
| // Run the samples if this file is run directly | ||
| if (require.main === module) { | ||
| main(); | ||
| } | ||
|
|
||
| module.export = { viewDatasetAccessPolicy, viewTableOrViewAccessPolicy } | ||
| Original file line number | Diff line number | Diff line change | ||
|---|---|---|---|---|
| @@ -0,0 +1,27 @@ | ||||
| { | ||||
| "name": "bigquery-cloud-client", | ||||
| "description": "Big Query Cloud Client Node.js for Google App", | ||||
| "version": "0.0.1", | ||||
| "private": true, | ||||
| "license": "Apache Version 2.0", | ||||
| "author": "Google Inc.", | ||||
|
||||
| // Copyright 2020 Google LLC |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I was checking the package.json files of other samples and all of them have Google Inc. in the author part.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These reference package.json files using Google Inc. might be outdated, see renderer/package.json#L6 from 2020 or retail/package.json#L4) from 2021
Also check b/169619920
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Anyway, you could ask your NodeJS lead for advice.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,58 @@ | ||
| // Copyright 2025 Google LLC | ||
| // | ||
| // Licensed under the Apache License, Version 2.0 (the "License"); | ||
| // you may not use this file except in compliance with the License. | ||
| // You may obtain a copy of the License at | ||
| // | ||
| // http://www.apache.org/licenses/LICENSE-2.0 | ||
| // | ||
| // Unless required by applicable law or agreed to in writing, software | ||
| // distributed under the License is distributed on an "AS IS" BASIS, | ||
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| // See the License for the specific language governing permissions and | ||
| // limitations under the License. | ||
|
|
||
| "use strict"; | ||
|
|
||
| const { BigQuery } = require("@google-cloud/bigquery"); | ||
|
|
||
| // [START bigquery_view_dataset_access_policy] | ||
| /** | ||
| * View access policies for a BigQuery dataset | ||
| * | ||
| * @param {object} [overrideValues] Optional parameters to override defaults | ||
hivanalejandro marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * @param {string} [overrideValues.datasetId] Dataset ID to view access policies | ||
| */ | ||
|
|
||
| async function viewDatasetAccessPolicy(overrideValues = {}) { | ||
| // Instantiate BigQuery client | ||
| const bigquery = new BigQuery(); | ||
|
|
||
| // Dataset from which to get the access policy | ||
| const datasetId = overrideValues.datasetId || "my_new_dataset"; | ||
|
|
||
| try { | ||
| // Prepares a reference to the dataset | ||
| const dataset = bigquery.dataset(datasetId); | ||
| const [metadata] = await dataset.getMetadata(); | ||
|
|
||
| // Shows the Access policy as a list of access entries | ||
| console.log("Access entries:", metadata.access); | ||
hivanalejandro marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| // Get properties for an AccessEntry | ||
| if (metadata.access && metadata.access.length > 0) { | ||
| console.log(`Details for Access entry 0 in dataset '${datasetId}':`); | ||
| console.log(`Role: '${metadata.access[0].role || "N/A"}'`); | ||
| console.log(`SpecialGroup: '${metadata.access[0].specialGroup || "N/A"}'`); | ||
| console.log(`UserByEmail: '${metadata.access[0].userByEmail || "N/A"}'`); | ||
| } | ||
| } catch (error) { | ||
| console.lerror(`Error viewing dataset access policy: ${error.message}`); | ||
| } | ||
| } | ||
|
|
||
| // [END bigquery_view_dataset_access_policy] | ||
|
|
||
| module.exports = { | ||
| viewDatasetAccessPolicy, | ||
| }; | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,71 @@ | ||
| // Copyright 2025 Google LLC | ||
| // | ||
| // Licensed under the Apache License, Version 2.0 (the "License"); | ||
| // you may not use this file except in compliance with the License. | ||
| // You may obtain a copy of the License at | ||
| // | ||
| // http://www.apache.org/licenses/LICENSE-2.0 | ||
| // | ||
| // Unless required by applicable law or agreed to in writing, software | ||
| // distributed under the License is distributed on an "AS IS" BASIS, | ||
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| // See the License for the specific language governing permissions and | ||
| // limitations under the License. | ||
|
|
||
| "use strict"; | ||
|
|
||
| const { BigQuery } = require("@google-cloud/bigquery"); | ||
|
|
||
| // [START bigquery_view_table_or_view_access_policy] | ||
| /** | ||
| * View access policies for a BigQuery table or view | ||
| * | ||
| * @param {object} [overrideValues] Optional parameters to override defaults | ||
hivanalejandro marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * @param {string} [overrideValues.projectId] Google Cloud project ID | ||
| * @param {string} [overrideValues.datasetId] Dataset ID where the table or view is located | ||
| * @param {string} [overrideValues.resourceName] Table or view name to get the access policy | ||
| * @throws {Error} If required parameters are missing or if there's an API error | ||
| */ | ||
|
|
||
| async function viewTableOrViewAccessPolicy(overrideValues = {}) { | ||
| // Initialize default values | ||
| const projectId = overrideValues.projectId || processors.env.GOOGLE_CLOUD_PROJECT; | ||
| const datasetId = overrideValues.datasetId || "my_new_dataset"; | ||
|
Check failure on line 33 in bigquery/cloud-client/src/viewTableOrViewAccessPolicy.js
|
||
| const resourceName = overrideValues.resourceName || "my_table"; | ||
|
|
||
| if (!projectId) { | ||
| throw new Error("Project ID is required. Set it in overrideValues or GOOGLE_CLOUD_PROJECT environment variable.") | ||
| } | ||
|
|
||
| try { | ||
| // // Instantiate BigQuery client | ||
| const bigquery = new BigQuery(); | ||
|
|
||
| // Get the IAM access policy from the table or view | ||
| const [policy] = await bigquery | ||
| .dataset(datasetId) | ||
| .table(resourceName) | ||
| .getIamPolicy(); | ||
|
|
||
| // Show policy details | ||
| console.log(`Access Policy details for table or view '${resourceName}':`); | ||
| console.log(`Bindings: ${JSON.stringify(policy.bindings, null, 2)}`); | ||
| console.log(`etag: ${policy.etag}`); | ||
| console.log(`version: ${policy.version}`); | ||
|
|
||
| return policy; | ||
| } catch (error) { | ||
| console.error(`Error viewing table/view access policy: ${error.message}`); | ||
| throw error; | ||
| } | ||
| } | ||
| // [END bigquery_view_table_or_view_access_policy] | ||
|
|
||
| // If this file is run directly, execute the function with default values | ||
| if (require.main === module) { | ||
| viewTableOrViewAccessPolicy().catch(console.error); | ||
| } | ||
|
|
||
| module.exports = { | ||
| viewTableOrViewAccessPolicy, | ||
| }; | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,99 @@ | ||
| // Copyright 2025 Google LLC | ||
| // | ||
| // Licensed under the Apache License, Version 2.0 (the "License"); | ||
| // you may not use this file except in compliance with the License. | ||
| // You may obtain a copy of the License at | ||
| // | ||
| // http://www.apache.org/licenses/LICENSE-2.0 | ||
| // | ||
| // Unless required by applicable law or agreed to in writing, software | ||
| // distributed under the License is distributed on an "AS IS" BASIS, | ||
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| // See the License for the specific language governing permissions and | ||
| // limitations under the License. | ||
|
|
||
| "use strict"; | ||
|
|
||
| const { assert } = require("chai"); | ||
| const sinon = require("sinon"); | ||
| const { BigQuery } = require("@google-cloud/bigquery") | ||
| const { viewDatasetAccessPolicy } = require("../src/viewDatasetAccessPolicy") | ||
|
|
||
| describe("viewDatasetAccessPolicy", () => { | ||
| let bigQueryStub; | ||
| let consoleLogSpy; | ||
|
|
||
| const sampleAccessEntry = { | ||
| role: "READER", | ||
| specialGroup: "projectReaders", | ||
| userByEmail: "[email protected]", | ||
| }; | ||
|
|
||
| beforeEach(() => { | ||
| // Stub BigQuery client | ||
| bigQueryStub = { | ||
| dataset: sinon.stub().returns({ | ||
| getMetadata: sinon.stub().resolves([ | ||
| { | ||
| access: [sampleAccessEntry], | ||
| }, | ||
| ]), | ||
| }), | ||
| }; | ||
|
|
||
| // Stub BigQuery constructor | ||
| sinon.stub(BigQuery.prototype, "dataset").callsFake(bigQueryStub.dataset); | ||
|
|
||
| // Spy on console.log | ||
| consoleLogSpy = sinon.spy(console, "log"); | ||
hivanalejandro marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| }); | ||
|
|
||
| afterEach(() => { | ||
| sinon.restore(); | ||
| }); | ||
|
|
||
| it("should display access policy details for a dataset", async () => { | ||
| const datasetId = "test_dataset"; | ||
|
|
||
| await viewDatasetAccessPolicy({ datasetId }); | ||
|
|
||
| // Verify BigQuery client was called correctly | ||
| assert.ok(consoleLogSpy.calledWith("Access entries:", [sampleAccessEntry])); | ||
hivanalejandro marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| assert.ok(consoleLogSpy.calledWith(`Details for Access entry 0 in dataset '${datasetId}':`)); | ||
| assert.ok(consoleLogSpy.calledWith("Role: READER")); | ||
| assert.ok(consoleLogSpy.calledWith("SpecialGroup: projectReaders")); | ||
| assert.ok(consoleLogSpy.calledWith("UserByEmail: [email protected]")); | ||
| }); | ||
|
|
||
| it("should handle datasets with no access entries", async () => { | ||
| // Override stub to return empty access array | ||
| bigQueryStub.dataset.returns({ | ||
| getMetadata: sinon.stub().resolves([ | ||
| { | ||
| access: [], | ||
| }, | ||
| ]), | ||
| }); | ||
|
|
||
| await viewDatasetAccessPolicy({ datasetId: "empty_dataset" }); | ||
|
|
||
| // Verify only the access entries message was logged | ||
| assert.ok(consoleLogSpy.calledWith("Access entries:", [])); | ||
| }); | ||
|
|
||
| it("should handle errors gracefully", async () => { | ||
| const errorMessage = "Dataset not found"; | ||
|
|
||
| // Override stub to throw error | ||
| bigQueryStub.dataset.returns({ | ||
| getMetadata: sinon.stub().rejects(new Error(errorMessage)), | ||
| }); | ||
|
|
||
| try { | ||
| await viewDatasetAccessPolicy({ datasetId: "non_existent_dataset" }); | ||
| assert.fail("Should have thrown an error"); | ||
| } catch (error) { | ||
| assert.include(error.message, errorMessage); | ||
| } | ||
| }); | ||
| }) | ||
Uh oh!
There was an error while loading. Please reload this page.