Skip to content

fix(GrantAccess): clarify update_row grants INSERT and fix erase_row description - #4442

Draft
krasnovdm wants to merge 1 commit into
ydb-platform:mainfrom
krasnovdm:fix/grant-update-row-insert-description
Draft

krasnovdm wants to merge 1 commit into
ydb-platform:mainfrom
krasnovdm:fix/grant-update-row-insert-description

Conversation

@krasnovdm

Copy link
Copy Markdown
Contributor

Problem

In the database Access tab (Grant access → Granular), the descriptions for update_row and erase_row are both shown as "Modify existing data rows with UPDATE operations." Both are misleading:

  • update_row actually authorizes all row writes — INSERT, UPSERT, REPLACE and UPDATE (it is also the right required to write to topics). There is no separate "insert" permission in the YDB access model, so users searching for one conclude inserts can't be granted, when update_row is exactly the permission to grant.
  • erase_row reuses the update_row text verbatim (copy-paste). erase_row is the DELETE permission.

The permission model (no insert_row; row writes gated by the UpdateRow access right, deletes by EraseRow) is defined in YDB core (viewer ACL dialect, ydb/core/viewer/viewer_acl.h).

Fix

Correct the two i18n descriptions in GrantAccess/i18n/en.json:

  • description_update-row → clarifies it covers INSERT/UPSERT/REPLACE/UPDATE (and topic writes), and that there is no separate insert permission.
  • description_erase-row → correct DELETE wording.

Pure i18n text change; no logic changes.

Screenshots

The update_row / erase_row tooltips render as the subtitle under each right in the Granular view (Rights.tsx → SingleRight).

…cription

update_row authorizes all row writes (INSERT/UPSERT/REPLACE/UPDATE and
topic writes), but its tooltip said "Modify existing data rows with
UPDATE operations", so users looked for a non-existent insert permission.
erase_row reused the same text by copy-paste though it is the DELETE right.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants