feat(python): expose Permissions and remaining user auth methods#3727
feat(python): expose Permissions and remaining user auth methods#3727ethanlin01x wants to merge 8 commits into
Conversation
63a8908 to
84a9f3b
Compare
Mirror the Rust Permissions, GlobalPermissions, StreamPermissions, and TopicPermissions types as PyO3 classes so user permissions can be built and inspected from Python. Stream and topic dict keys are typed u32 to match the wire format, so out-of-range IDs fail at construction instead of being silently truncated. The client methods that consume these classes follow in the next commits.
create_user hardcoded None for permissions, so every user came out unprivileged and UserInfoDetails gave no way to inspect grants. Wire the Permissions argument through create_user and add the permissions getter so grants round-trip through get_user. The credential helpers shared by the user tests move to tests/utils.py for the new enforcement tests.
Permissions set at creation were frozen: there was no way to grant, replace, or revoke them afterwards. update_permissions is a full replacement and None clears the permissions entirely, matching the Rust client semantics.
Password rotation required deleting and recreating the user, losing its id and permissions. change_password verifies the current password server-side, and a user can rotate its own credentials without any admin permission.
Sessions could only be abandoned by dropping the connection, leaving the server-side session authenticated until the socket closed. logout_user ends the session explicitly; a later login_user on the same client starts a fresh one.
84a9f3b to
22bc32c
Compare
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #3727 +/- ##
============================================
+ Coverage 74.34% 74.38% +0.03%
Complexity 950 950
============================================
Files 1303 1304 +1
Lines 148712 148951 +239
Branches 124225 124225
============================================
+ Hits 110562 110793 +231
- Misses 34673 34681 +8
Partials 3477 3477
🚀 New features to boost your workflow:
|
|
/ready |
| #[new] | ||
| #[pyo3(signature = (global_=None, streams=None))] | ||
| fn new( | ||
| #[gen_stub(override_type(type_repr = "GlobalPermissions | None"))] global_: Option< |
There was a problem hiding this comment.
Why global_? why not global?
There was a problem hiding this comment.
global is a reserved keyword in Python.
The trailing underscore follows the PEP 8 convention for names that collide with keywords (like class_). An alternative would be global_permissions, but I kept global_ to mirror the Rust field name. Let me know if you'd prefer the longer name.
There was a problem hiding this comment.
Let's remove the following tests:
test_all_global_permission_flags_set_togethertest_all_stream_permission_flags_set_togethertest_all_topic_permission_flags_set_together
they do not add much to the current test set.
There was a problem hiding this comment.
Let us add the following tests:
- User without
manage_userscannot update another user’s permissions. - User with
manage_userscan update another user’s permissions. - Failed update leaves target permissions unchanged.
- calling logout twice fails
| async def test_create_user_without_permissions_has_none( | ||
| self, iggy_client: IggyClient, unique_name | ||
| ): |
There was a problem hiding this comment.
test_create_user_without_permissions_has_none is valid but need not be a separate integration test. Add permissions is None assertions to existing test_create_and_get_user.
|
/ready |
Which issue does this PR address?
Closes #3726
Rationale
The Python SDK could create users but not grant them access to anything:
create_userhardcodedNonefor permissions, andupdate_permissions,change_password, and logout_user` were unexposed.What changed?
Before, the Python SDK could create users but not grant them access to anything:
create_userhardcodedNonefor permissions, andupdate_permissions,change_password, andlogout_userwere unexposed.Now the Rust
Permissionshierarchy is mirrored as PyO3 classes,create_usertakes an optionalpermissionsargument,UserInfoDetailsexposes apermissionsgetter, and the three missing methods complete theUserClientsurface, with the underlying Rust client handling the wire encoding.Local Execution
AI Usage
Claude was used to help generate and review this PR and all the changes are checked by the human.