-
Notifications
You must be signed in to change notification settings - Fork 36
feat: support conditional policies #110
Changes from all commits
67e52ce
84fcfea
145f7a0
ac1fd6e
2c8724b
c90dbb0
b0a617f
9dbfc2d
54ad076
ff49620
298b2be
aaebba4
a5f63ea
4873b73
c853a84
c64e55a
d2fab21
86cd863
085959d
174e8c4
14e1aac
fdb040a
42199d1
bbb708a
7f0e33e
108faec
79126b5
505f9bc
a89ef0c
f0b5085
9f5e600
8580f5a
9fe4358
8f48a15
615ba06
2b56641
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,112 @@ | ||
/* | ||
* Copyright 2020 Google LLC | ||
* | ||
* Licensed under the Apache License, Version 2.0 (the "License"); | ||
* you may not use this file except in compliance with the License. | ||
* You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package com.google.cloud; | ||
|
||
import static com.google.common.base.Predicates.in; | ||
import static com.google.common.base.Predicates.not; | ||
|
||
import com.google.api.core.BetaApi; | ||
import com.google.auto.value.AutoValue; | ||
import com.google.common.base.Predicate; | ||
import com.google.common.collect.Collections2; | ||
import com.google.common.collect.ImmutableList; | ||
import com.google.common.collect.Lists; | ||
import java.util.Arrays; | ||
import java.util.Collection; | ||
import java.util.List; | ||
import javax.annotation.Nullable; | ||
|
||
/** | ||
* Class for Identity and Access Management (IAM) policies. IAM policies are used to specify access | ||
* settings for Cloud Platform resources. A policy is a list of bindings. A binding assigns a set of | ||
* identities to a role, where the identities can be user accounts, Google groups, Google domains, | ||
* and service accounts. A role is a named list of permissions defined by IAM. | ||
* | ||
* @see <a href="https://cloud.google.com/iam/docs/reference/rest/v1/Policy">Policy</a> | ||
*/ | ||
@BetaApi("This is a Beta API is not stable yet and may change in the future.") | ||
@AutoValue | ||
public abstract class Binding { | ||
chingor13 marked this conversation as resolved.
Show resolved
Hide resolved
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'd very much recommend Javadoc for public types and public methods that aren't obvious. |
||
/** Get IAM Policy Binding Role */ | ||
public abstract String getRole(); | ||
|
||
/** Get IAM Policy Binding Members */ | ||
public abstract ImmutableList<String> getMembers(); | ||
|
||
/** Get IAM Policy Binding Condition */ | ||
@Nullable | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why Either is okay, but it's interesting that you're using both patterns in the same class. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I picked Nullable because it made more sense to me in this case. I'm not well versed in Optional's. Both patterns? Not sure I understand. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Sorry, I thought for some reason that you were also using |
||
public abstract Condition getCondition(); | ||
|
||
/** Create a Binding.Builder from an existing Binding */ | ||
public abstract Builder toBuilder(); | ||
|
||
/** Create a new Binding.Builder */ | ||
public static Builder newBuilder() { | ||
List<String> emptyMembers = ImmutableList.of(); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. You could just inline |
||
return new AutoValue_Binding.Builder().setMembers(emptyMembers); | ||
} | ||
|
||
@AutoValue.Builder | ||
public abstract static class Builder { | ||
/** | ||
* Set IAM Role for Policy Binding | ||
* | ||
* @throws NullPointerException if the role is null. | ||
*/ | ||
public abstract Builder setRole(String role); | ||
|
||
/** | ||
* Set IAM Members for Policy Binding | ||
* | ||
* @throws NullPointerException if a member is null. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. You don't really need to repeat this everywhere. It's better to use |
||
*/ | ||
public abstract Builder setMembers(Iterable<String> members); | ||
|
||
/** Set IAM Condition for Policy Binding */ | ||
public abstract Builder setCondition(Condition condition); | ||
|
||
/** Internal use to getMembers() in addMembers() and removeMembers() */ | ||
abstract ImmutableList<String> getMembers(); | ||
|
||
/** | ||
* Add members to Policy Binding. | ||
* | ||
* @throws NullPointerException if a member is null. | ||
*/ | ||
public Builder addMembers(String member, String... moreMembers) { | ||
ImmutableList.Builder<String> membersBuilder = ImmutableList.builder(); | ||
membersBuilder.addAll(getMembers()); | ||
membersBuilder.addAll(Lists.asList(member, moreMembers)); | ||
setMembers(membersBuilder.build()); | ||
return this; | ||
} | ||
|
||
/** | ||
* Remove members to Policy Binding. | ||
* | ||
* @throws NullPointerException if a member is null. | ||
*/ | ||
public Builder removeMembers(String... members) { | ||
Predicate<String> selectMembersNotInList = not(in(Arrays.asList(members))); | ||
Collection<String> filter = Collections2.filter(getMembers(), selectMembersNotInList); | ||
setMembers(filter); | ||
return this; | ||
} | ||
|
||
public abstract Binding build(); | ||
} | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,65 @@ | ||
/* | ||
* Copyright 2020 Google LLC | ||
* | ||
* Licensed under the Apache License, Version 2.0 (the "License"); | ||
* you may not use this file except in compliance with the License. | ||
* You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package com.google.cloud; | ||
|
||
import com.google.api.core.BetaApi; | ||
import com.google.auto.value.AutoValue; | ||
|
||
/** | ||
* Class for Identity and Access Management (IAM) policies. IAM policies are used to specify access | ||
* settings for Cloud Platform resources. A policy is a list of bindings. A binding assigns a set of | ||
* identities to a role, where the identities can be user accounts, Google groups, Google domains, | ||
* and service accounts. A role is a named list of permissions defined by IAM. | ||
* | ||
* @see <a href="https://cloud.google.com/iam/docs/reference/rest/v1/Policy">Policy</a> | ||
* @see <a href="https://cloud.google.com/iam/docs/conditions-overview">IAM Conditions</a> | ||
*/ | ||
@BetaApi("This is a Beta API is not stable yet and may change in the future.") | ||
@AutoValue | ||
public abstract class Condition { | ||
/** Get IAM Policy Binding Condition Title */ | ||
public abstract String getTitle(); | ||
|
||
/** Get IAM Policy Binding Condition Description */ | ||
public abstract String getDescription(); | ||
|
||
/** Get IAM Policy Binding Condition Expression */ | ||
public abstract String getExpression(); | ||
|
||
/** Create a new Condition.Builder from an existing Condition */ | ||
public abstract Builder toBuilder(); | ||
|
||
/** Create a new Condition.Builder */ | ||
public static Builder newBuilder() { | ||
return new AutoValue_Condition.Builder(); | ||
} | ||
|
||
@AutoValue.Builder | ||
public abstract static class Builder { | ||
/** Set IAM Policy Binding Condition Title */ | ||
public abstract Builder setTitle(String title); | ||
|
||
/** Set IAM Policy Binding Condition Description */ | ||
public abstract Builder setDescription(String description); | ||
|
||
/** Set IAM Policy Binding Condition Expression */ | ||
public abstract Builder setExpression(String expression); | ||
|
||
/** Build Builder which creates a Condition instance */ | ||
public abstract Condition build(); | ||
} | ||
} |
Uh oh!
There was an error while loading. Please reload this page.