Documentation
¶
Overview ¶
Package bigqueryread composes the released BigQuery driver with DataTug policies.
Index ¶
Constants ¶
const MaxInputBytes = 256 << 10
Variables ¶
var ErrIdentity = errors.New("google execution identity or granted scopes unavailable; explicitly sign in with Google BigQuery read-only and openid scopes, then preview again")
var ErrInput = errors.New("invalid BigQuery input: expected bounded typed JSON")
Functions ¶
func DecodeLimit ¶
DecodeLimit is used only for bounded preview/result recovery envelopes.
Types ¶
type Condition ¶
type Condition struct {
Op string `json:"op,omitempty"`
Left *Expression `json:"left,omitempty"`
Right *Expression `json:"right,omitempty"`
And []Condition `json:"and,omitempty"`
Or []Condition `json:"or,omitempty"`
IsNull *Column `json:"isNull,omitempty"`
IsNotNull *Column `json:"isNotNull,omitempty"`
}
type Expression ¶
type Expression struct {
Field string `json:"field,omitempty"`
Param string `json:"param,omitempty"`
Value json.RawMessage `json:"value,omitempty"`
}
type GoogleProvider ¶
type GoogleProvider struct {
// contains filtered or unexported fields
}
GoogleProvider uses the existing explicit Google login's refresh-token source. It never opens a browser or uses ADC. Granted scope comes only from the Google token response, and the SAME token verifies sub at fixed HTTPS UserInfo.
func NewADCProvider ¶
func NewADCProvider(dir string, enableCancel bool) (*GoogleProvider, error)
NewADCProvider reads user-controlled ADC only after explicit --auth adc. Scope options request grants but cannot attest them. Workload ADC is refused; its authoritative subject requires a separate trusted operator provider.
func NewGoogleProvider ¶
func NewGoogleProvider(dir string, enableCancel bool) (*GoogleProvider, error)
NewGoogleProvider must follow NewFileLedger admission of dir's private path. The nonce is nonsecret and contains no token, email, policy label or credential.
func (*GoogleProvider) Authorize ¶
func (p *GoogleProvider) Authorize(ctx context.Context, guarded http.RoundTripper) (bigquery.Identity, http.RoundTripper, error)
func (*GoogleProvider) AuthorizeToken ¶
func (p *GoogleProvider) AuthorizeToken(ctx context.Context, token *oauth2.Token, guarded http.RoundTripper) (bigquery.Identity, http.RoundTripper, error)
AuthorizeToken attests the exact token returned by an explicit Google consent exchange. It is used to compare that consent with the credential store before connect reports success; it never stores the access token or opens consent.
type Input ¶
type Input struct {
Profile bigquery.SourceProfile `json:"profile"`
Query QueryShape `json:"query"`
}
Input is an explicit scalar DTQL query and reviewed native source profile. QueryShape intentionally excludes SQL, joins, subqueries, aliases and offsets.