Skip to main content
has_permission(principal=, object=None, object_type=None, permission=None, options=)[source]

Checks if the specified user has the specified permission on the specified object.

Parameters

principal (str) –

Name of the user for which the permission is being checked. Must be an existing user. If blank, will use the current user. The default value is ‘’.

object (str) –

Name of object to check for the requested permission. It is recommended to use a fully-qualified name when possible.

object_type (str) –

The type of object being checked. Allowed values are:

  • catalog – External Catalog

  • context – Context

  • credential – Credential

  • datasink – Data Sink

  • datasource – Data Source

  • directory – KiFS File Directory

  • graph – A Graph object

  • proc – UDF Procedure

  • schema – Schema

  • sql_proc – SQL Procedure

  • system – System-level access

  • table – Database Table

  • table_monitor – Table monitor

permission (str) –

Permission to check for. Allowed values are:

  • admin – Full read/write and administrative access on the object.

  • connect – Connect access on the given data source or data sink.

  • create – Ability to create new objects of this type.

  • delete – Delete rows from tables.

  • execute – Ability to Execute the Procedure object.

  • insert – Insert access to tables.

  • monitor – Monitor logs and statistics.

  • read – Ability to read, list and use the object.

  • send_alert – Ability to send system alerts.

  • update – Update access to the table.

  • user_admin – Access to administer users and roles that do not have system_admin permission.

  • write – Access to write, change and delete objects.

options (dict of str to str) –

Optional parameters. Allowed keys are:

  • no_error_if_not_exists – If false will return an error if the provided input parameter object does not exist or is blank. If true then it will return false for output parameter has_permission. Allowed values are:

    • true

    • false

    The default value is ‘false’.

The default value is an empty dict ( ).

Returns

A dict with the following entries–

principal (str) –

Value of input parameter principal.

object (str) –

Fully-qualified value of input parameter object.

object_type (str) –

Value of input parameter object_type.

permission (str) –

Value of input parameter permission.

has_permission (bool) –

Indicates whether the specified user has the specified permission on the specified target. Allowed values are:

  • True – User has the effective queried permission.

  • False – User does not have the queried permission.

filters (dict of str to str) –

Map of column/filters that have been granted.

info (dict of str to str) –

Additional information.