Skip to content

Implement ACL abstraction for Cloud Storage API #285

Description

@silvolu

@ryanseys' refactoring proposal contained a stub at an ACL API that we deprioritized in favor of support for more API.
The time has come to implement it. I like the gcloud-python approach, where you can do things like:

bucket.acl.user('[email protected]').grant_read()
bucket.acl.all_authenticated().grant_write()
bucket.acl.save()

Activity

  1. added this to the milestone on Nov 6, 2014
  2. stephenplusplus commented on Nov 7, 2014

    @stephenplusplus
    Contributor

    Snipped this out from the post linked above.

    ACL class

    var myACL = storage.acl(['entity', 'permission', 'entity2', 'permission2']);

    Buckets:

    myBucket.clearDefaultACL(cb);
    myBucket.getDefaultACL(cb);
    myBucket.setDefaultACL(myACL, cb);
    
    myBucket.clearACL(cb);
    myBucket.getACL(cb);
    myBucket.setACL(myACL, cb);

    Files:

    myFile.clearACL(cb);
    myFile.getACL(cb);
    myFile.setACL(myACL, cb);

    And here's another variation to consider, which is more like @silvolu's model above. The demos below use myBucket but should work with myFile as well.

    myBucket.acl.grant('[email protected]', ['read', 'write'], function(err) {});
    myBucket.acl.revoke('allUsers', 'read', function(err) {});
    
    // array variations:
    myBucket.acl.grant(['[email protected]', 'someotherdude'], ['read', 'write'], function(err) {});
    myBucket.acl.revoke(['[email protected]', 'allAuthenticatedUsers'], 'write', function(err) {});
    
    myBucket.acl.get(function(err, acl) {
      acl = [
        { account: '[email protected]', permissions: ['read', 'write'] },
        { account: 'someotherdude', permissions: ['read', 'write'] }
      ]
    });
    
    myBucket.acl.get('[email protected]', function(err, acl) {
      acl = {
        account: '[email protected]', permissions: ['read', 'write']
      }
    });
    • Maybe get/set/delete instead of get/grant/revoke?
    • Should we allow easier ACL setting when creating a bucket, or is letting them configure the metadata object enough?
  3. stephenplusplus commented on Nov 14, 2014

    @stephenplusplus
    Contributor

    * bump * :)

  4. ryanseys commented on Nov 14, 2014

    @ryanseys
    Contributor

    Whoops overlooked this. So just to simplify we have:

    Get acl is .get([user,] cb)
    Set acl is .grant(users, sharedPermissions, cb) and .revoke(users, permission, cb)

    Questions:

    • How will be setting default permissions for new objects in a bucket?
    • Should allAuthenticatedUsers be abstracted to its own method call? e.g. grantAllAuthenticated() or something?
    • How can I make all my bucket objects public for everyone, including new objects that I might add later? (I imagine this is a common use case)
  5. silvolu commented on Nov 14, 2014

    @silvolu
    ContributorAuthor

    How will be setting default permissions for new objects in a bucket?

    Something like:

    acl = [
        { account: '[email protected]', permissions: ['read', 'write'] },
        { account: 'someotherdude', permissions: ['read', 'write'] }
      ]
    myBucket.defaultAcl.set(acl, function(err, acl) {
      // whatever
    });

    Should allAuthenticatedUsers be abstracted to its own method call? e.g. grantAllAuthenticated() or something?

    Might be nice as an addition. I guess we should provide both grant/revokeAllAuthenticated.

    How can I make all my bucket objects public for everyone, including new objects that I might add later? (I imagine this is a common use case)

    You mean how to make that happen or how to better expose it?

    (edit): replaced get with set in the example
    (edit): I think the example makes more sense now

  6. ryanseys commented on Nov 24, 2014

    @ryanseys
    Contributor

    Fixed by #304

  7. modified the milestones: , Storage Stable on Feb 2, 2015
  8. 27 remaining items

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

🚨This issue needs some love.api: storageIssues related to the Cloud Storage API.triage meI really want to be triaged.

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions