Commit f6f1972
Task LAV-2685: REST /api/v2 users, roles and database roles (object surface only, no grants) (#3231)
* task LAV-2685: WIP — commit stranded agent work
* Task LAV-2685: REST /api/v2 users, roles and database roles
Complete the RBAC object surface (list/create/fetch/delete/createOrAlter/
clone/tag trio) for users, roles and database roles via the generic REST
registry, with snapshots captured against real Snowflake. Grants stay 501.
- Parser: route ALTER USER SET/UNSET TAG through the shared object-tag
interceptor (Statement::SetTags) so a qualified tag key parses, which the
generic parse_alter_user grammar cannot. Exclude Snowflake from the
cross-dialect ALTER USER tag assertions and cover it in the Snowflake suite,
mirroring the ALTER ROLE precedent.
- Projection fixes (real-Snowflake parity): map SHOW USERS'
default_secondary_roles (["ALL"]) to the scalar REST enum; treat the
V1-wire "1" boolean as truthy so has_password/has_rsa_public_key report
correctly; render a database role's empty comment as "" (not null); a clone
does not inherit its source's comment.
- error_ident: users and roles lower-case the echoed identifier in the
002003 envelope (databases/warehouses stay verbatim), matching capture.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent b9439c1 commit f6f1972
5 files changed
Lines changed: 285 additions & 193 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4147 | 4147 | | |
4148 | 4148 | | |
4149 | 4149 | | |
| 4150 | + | |
| 4151 | + | |
| 4152 | + | |
4150 | 4153 | | |
4151 | 4154 | | |
4152 | 4155 | | |
| |||
7823 | 7826 | | |
7824 | 7827 | | |
7825 | 7828 | | |
| 7829 | + | |
7826 | 7830 | | |
7827 | 7831 | | |
7828 | 7832 | | |
7829 | 7833 | | |
7830 | 7834 | | |
7831 | 7835 | | |
7832 | 7836 | | |
| 7837 | + | |
| 7838 | + | |
| 7839 | + | |
7833 | 7840 | | |
7834 | 7841 | | |
7835 | 7842 | | |
| |||
0 commit comments