Skip to content

Commit f6f1972

Browse files
hovaescoclaude
andauthored
Task LAV-2685: REST /api/v2 users, roles and database roles (object surface only, no grants) (#3231)
* task LAV-2685: WIP — commit stranded agent work * Task LAV-2685: REST /api/v2 users, roles and database roles Complete the RBAC object surface (list/create/fetch/delete/createOrAlter/ clone/tag trio) for users, roles and database roles via the generic REST registry, with snapshots captured against real Snowflake. Grants stay 501. - Parser: route ALTER USER SET/UNSET TAG through the shared object-tag interceptor (Statement::SetTags) so a qualified tag key parses, which the generic parse_alter_user grammar cannot. Exclude Snowflake from the cross-dialect ALTER USER tag assertions and cover it in the Snowflake suite, mirroring the ALTER ROLE precedent. - Projection fixes (real-Snowflake parity): map SHOW USERS' default_secondary_roles (["ALL"]) to the scalar REST enum; treat the V1-wire "1" boolean as truthy so has_password/has_rsa_public_key report correctly; render a database role's empty comment as "" (not null); a clone does not inherit its source's comment. - error_ident: users and roles lower-case the echoed identifier in the 002003 envelope (databases/warehouses stay verbatim), matching capture. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1 parent b9439c1 commit f6f1972

5 files changed

Lines changed: 285 additions & 193 deletions

File tree

‎src/ast/mod.rs‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4147,6 +4147,9 @@ pub enum Statement {
41474147
name: ObjectName,
41484148
/// Optional `COMMENT = '...'` clause.
41494149
comment: Option<String>,
4150+
/// Optional `CLONE <source>` clause: the (optionally database-qualified)
4151+
/// source database role this one is cloned from.
4152+
clone: Option<ObjectName>,
41504153
},
41514154
/// ```sql
41524155
/// CREATE SECRET
@@ -7823,13 +7826,17 @@ impl fmt::Display for Statement {
78237826
if_not_exists,
78247827
name,
78257828
comment,
7829+
clone,
78267830
} => {
78277831
write!(
78287832
f,
78297833
"CREATE {or_replace}DATABASE ROLE {if_not_exists}{name}",
78307834
or_replace = if *or_replace { "OR REPLACE " } else { "" },
78317835
if_not_exists = if *if_not_exists { "IF NOT EXISTS " } else { "" },
78327836
)?;
7837+
if let Some(clone) = clone {
7838+
write!(f, " CLONE {clone}")?;
7839+
}
78337840
if let Some(comment) = comment {
78347841
write!(
78357842
f,

0 commit comments

Comments
 (0)