Repository navigation
Implement ACL abstraction for Cloud Storage API #285
Description
Activity
Snipped this out from the post linked above.
ACL class
var myACL = storage.acl(['entity', 'permission', 'entity2', 'permission2']);
Buckets:
myBucket.clearDefaultACL(cb); myBucket.getDefaultACL(cb); myBucket.setDefaultACL(myACL, cb); myBucket.clearACL(cb); myBucket.getACL(cb); myBucket.setACL(myACL, cb);
Files:
myFile.clearACL(cb); myFile.getACL(cb); myFile.setACL(myACL, cb);
And here's another variation to consider, which is more like @silvolu's model above. The demos below use
myBucketbut should work withmyFileas well.myBucket.acl.grant('[email protected]', ['read', 'write'], function(err) {}); myBucket.acl.revoke('allUsers', 'read', function(err) {}); // array variations: myBucket.acl.grant(['[email protected]', 'someotherdude'], ['read', 'write'], function(err) {}); myBucket.acl.revoke(['[email protected]', 'allAuthenticatedUsers'], 'write', function(err) {}); myBucket.acl.get(function(err, acl) { acl = [ { account: '[email protected]', permissions: ['read', 'write'] }, { account: 'someotherdude', permissions: ['read', 'write'] } ] }); myBucket.acl.get('[email protected]', function(err, acl) { acl = { account: '[email protected]', permissions: ['read', 'write'] } });
- Maybe get/set/delete instead of get/grant/revoke?
- Should we allow easier ACL setting when creating a bucket, or is letting them configure the metadata object enough?
* bump * :)
Whoops overlooked this. So just to simplify we have:
Get acl is
.get([user,] cb)
Set acl is.grant(users, sharedPermissions, cb)and.revoke(users, permission, cb)Questions:
- How will be setting default permissions for new objects in a bucket?
- Should
allAuthenticatedUsersbe abstracted to its own method call? e.g.grantAllAuthenticated()or something? - How can I make all my bucket objects public for everyone, including new objects that I might add later? (I imagine this is a common use case)
How will be setting default permissions for new objects in a bucket?
Something like:
acl = [ { account: '[email protected]', permissions: ['read', 'write'] }, { account: 'someotherdude', permissions: ['read', 'write'] } ] myBucket.defaultAcl.set(acl, function(err, acl) { // whatever });
Should allAuthenticatedUsers be abstracted to its own method call? e.g. grantAllAuthenticated() or something?
Might be nice as an addition. I guess we should provide both grant/revokeAllAuthenticated.
How can I make all my bucket objects public for everyone, including new objects that I might add later? (I imagine this is a common use case)
You mean how to make that happen or how to better expose it?
(edit): replaced get with set in the example
(edit): I think the example makes more sense nowFixed by #304
- addedapi: storageIssues related to the Cloud Storage API.Issues related to the Cloud Storage API.
on Feb 2, 2015 - added🚨This issue needs some love.This issue needs some love.triage meI really want to be triaged.I really want to be triaged.
on Apr 6, 2020 27 remaining items
- added a commit that references this issue
on Feb 5, 2026 - added a commit that references this issue
on Feb 5, 2026 - added a commit that references this issue
on Feb 17, 2026 - added a commit that references this issue
on Feb 23, 2026 - added a commit that references this issue
on Feb 25, 2026 - added 2 commits that reference this issue
on Feb 25, 2026 - added 2 commits that reference this issue
on Feb 26, 2026 - added a commit that references this issue
on Mar 18, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on May 5, 2026
@ryanseys' refactoring proposal contained a stub at an ACL API that we deprioritized in favor of support for more API.
The time has come to implement it. I like the gcloud-python approach, where you can do things like: