import (
"context"
"fmt"
"cloud.google.com/go/bigquery"
)
// updateViewDelegated demonstrates the setup of an authorized view, which allows access to a view's results
// without the caller having direct access to the underlying source data.
func updateViewDelegated(projectID, srcDatasetID, viewDatasetID, viewID string) error {
// projectID := "my-project-id"
// srcDatasetID := "sourcedata"
// viewDatasetID := "views"
// viewID := "myview"
ctx := context.Background()
client, err := bigquery.NewClient(ctx, projectID)
if err != nil {
return fmt.Errorf("bigquery.NewClient: %w", err)
}
defer client.Close()
srcDataset := client.Dataset(srcDatasetID)
viewDataset := client.Dataset(viewDatasetID)
view := viewDataset.Table(viewID)
// First, we'll add a group to the ACL for the dataset containing the view. This will allow users within
// that group to query the view, but they must have direct access to any tables referenced by the view.
vMeta, err := viewDataset.Metadata(ctx)
if err != nil {
return err
}
vUpdateMeta := bigquery.DatasetMetadataToUpdate{
Access: append(vMeta.Access, &bigquery.AccessEntry{
Role: bigquery.ReaderRole,
EntityType: bigquery.GroupEmailEntity,
Entity: "example-analyst-group@google.com",
}),
}
if _, err := viewDataset.Update(ctx, vUpdateMeta, vMeta.ETag); err != nil {
return err
}
// Now, we'll authorize a specific view against a source dataset, delegating access enforcement.
// Once this has been completed, members of the group previously added to the view dataset's ACL
// no longer require access to the source dataset to successfully query the view.
srcMeta, err := srcDataset.Metadata(ctx)
if err != nil {
return err
}
srcUpdateMeta := bigquery.DatasetMetadataToUpdate{
Access: append(srcMeta.Access, &bigquery.AccessEntry{
EntityType: bigquery.ViewEntity,
View: view,
}),
}
if _, err := srcDataset.Update(ctx, srcUpdateMeta, srcMeta.ETag); err != nil {
return err
}
return nil
}