Skip to main content

uqa_sql/catalog/
security.rs

1//
2// Unified Query Algebra
3//
4// Copyright (c) 2023-2026 Cognica, Inc.
5//
6
7use std::collections::BTreeMap;
8pub mod acl_command;
9pub mod acl_warning;
10pub mod columns;
11pub mod dependencies;
12mod role_bindings;
13pub mod schema;
14pub mod schema_binding;
15pub use schema_binding::BoundSchemaSecurity;
16pub mod table;
17pub mod table_binding;
18pub use table_binding::BoundTableSecurity;
19pub use uqa_core::catalog_acl::{AclGrantee, TableAclEntry, TablePrivileges};
20
21/// Complete table-shaped relation security state. Ownership and ACL changes are published through one value so readers cannot observe a torn authorization state.
22#[derive(Debug, Clone, PartialEq, Eq)]
23pub struct TableSecurity {
24    pub role_owner: String,
25    pub acl: Option<Vec<TableAclEntry>>,
26    pub column_acls: BTreeMap<String, Vec<TableAclEntry>>,
27}
28
29impl TableSecurity {
30    pub fn from_legacy(row: uqa_core::catalog_acl::LegacyRelationSecurity) -> Self {
31        Self {
32            role_owner: row.role_owner,
33            acl: row.acl,
34            column_acls: row.column_acls,
35        }
36    }
37
38    pub fn owner(role_owner: impl Into<String>) -> Self {
39        Self {
40            role_owner: role_owner.into(),
41            acl: None,
42            column_acls: BTreeMap::new(),
43        }
44    }
45}
46
47#[derive(Debug, Clone, PartialEq, Eq)]
48pub struct SchemaSecurity {
49    pub role_owner: String,
50    pub acl: Option<Vec<uqa_core::catalog_schema::SchemaAclEntry>>,
51}
52
53impl SchemaSecurity {
54    pub fn from_row(row: uqa_core::catalog_schema::SchemaRow) -> (String, Self) {
55        (
56            row.name,
57            Self {
58                role_owner: row.role_owner,
59                acl: row.acl,
60            },
61        )
62    }
63
64    pub fn row(&self, name: impl Into<String>) -> uqa_core::catalog_schema::SchemaRow {
65        uqa_core::catalog_schema::SchemaRow {
66            name: name.into(),
67            role_owner: self.role_owner.clone(),
68            acl: self.acl.clone(),
69        }
70    }
71
72    pub fn legacy(name: &str) -> Self {
73        let (_, security) = Self::from_row(uqa_core::catalog_schema::SchemaRow::legacy(name));
74        security
75    }
76}
77
78pub mod schema_inquiry;
79
80pub mod database;
81pub mod database_inquiry;
82
83pub mod sequence;
84pub mod sequence_binding;
85pub use sequence_binding::BoundSequenceSecurity;
86pub mod sequence_grants;
87pub mod sequence_inquiry;
88
89#[derive(Debug, Clone, PartialEq, Eq)]
90pub struct SequenceSecurity {
91    pub role_owner: String,
92    pub acl: Option<Vec<uqa_core::catalog_sequence::SequenceAclEntry>>,
93}
94
95pub mod table_inquiry;
96
97pub mod view_ownership;
98
99pub mod builtin_routines;
100pub mod grants;
101pub mod object_acl;
102pub mod system_relations;
103pub mod table_grants;
104pub mod type_inquiry;
105pub mod type_privileges;
106
107pub mod view_authorization;
108
109pub mod ownership;
110
111#[cfg(test)]
112mod owner_privileges;