Skip to content

access_controller

access_controller

Fileset access control using the relationship system.

DomoFilesetAccessController

DomoFilesetAccessController(auth: DomoAuth, parent)

Bases: DomoAccessRelationshipController

Access controller for Domo filesets.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
24
25
26
27
def __init__(self, auth: DomoAuth, parent):
    super().__init__(auth=auth, parent_object=parent)
    self.parent = parent
    self.relationships: list[Relationship] = []

add_owners async

add_owners(
    user_id: int,
    *,
    context: RouteContext | None = None,
    **context_kwargs
) -> bool

Deprecated alias for transfer_owner — which TRANSFERS, not adds.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
async def add_owners(
    self,
    user_id: int,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> bool:
    """Deprecated alias for `transfer_owner` — which TRANSFERS, not adds."""
    warnings.warn(
        "DomoFilesetAccessController.add_owners is deprecated; use "
        "transfer_owner instead. It TRANSFERS ownership — the current owner "
        "is displaced and there is no undo (remove_owners raises "
        "NotImplementedError).",
        DeprecationWarning,
        stacklevel=2,
    )
    return await self.transfer_owner(
        user_id=user_id, context=context, **context_kwargs
    )

create_relationship async

create_relationship(
    target_entity_id: str,
    target_entity_type: EntityType,
    relationship_type: RelationshipType,
    **kwargs
) -> bool

Create an access relationship for the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
async def create_relationship(
    self,
    target_entity_id: str,
    target_entity_type: EntityType,
    relationship_type: RelationshipType,
    **kwargs,
) -> bool:
    """Create an access relationship for the fileset."""
    return await self.share(
        user_ids=(
            [int(target_entity_id)]
            if target_entity_type == EntityType.USER
            else None
        ),
        group_ids=(
            [int(target_entity_id)]
            if target_entity_type == EntityType.GROUP
            else None
        ),
        **kwargs,
    )

get_accesslist async

get_accesslist(
    return_raw: bool = False,
    *,
    context: RouteContext | None = None,
    **context_kwargs
) -> list[Relationship]

Get access list for the fileset as relationships.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
async def get_accesslist(
    self,
    return_raw: bool = False,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> list[Relationship]:
    """Get access list for the fileset as relationships."""
    context = RouteContext.build_context(context=context, **context_kwargs)

    res = await fileset_routes.get_fileset_access(
        auth=self.auth,
        fileset_id=self.parent_id,
        context=context,
    )

    if return_raw:
        return res

    relationships: list[Relationship] = []
    access_entries: list[dict[str, Any]] = []

    if isinstance(res.response, dict):
        access_entries = res.response.get("fileSetAccess", [])

    for entry in access_entries:
        entity_id = entry.get("entityId")
        entity_type = entry.get("entityType")
        permission = entry.get("permission")
        if entity_id is None or not entity_type:
            continue
        relationships.append(
            Relationship(
                from_entity_id=str(entity_id),
                from_entity_type=(
                    EntityType.GROUP
                    if str(entity_type).upper() == "GROUP"
                    else EntityType.USER
                ),
                to_entity_id=str(self.parent_id),
                to_entity_type=EntityType.DATASET,  # FILESET not in EntityType enum
                relationship_type=self._map_permission(permission),
                metadata=entry,
            )
        )

    self.relationships = relationships
    self.invalidate_cache()
    return relationships

get_direct_relationships async

get_direct_relationships() -> list[Relationship]

Get direct relationships for the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
33
34
35
async def get_direct_relationships(self) -> list[Relationship]:
    """Get direct relationships for the fileset."""
    return await self.get_accesslist()

get_owners async

get_owners(
    *, context: RouteContext | None = None, **context_kwargs
) -> list[Relationship]

Get owner relationships for the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
async def get_owners(
    self,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> list[Relationship]:
    """Get owner relationships for the fileset."""
    if not self.relationships:
        await self.get_accesslist(context=context, **context_kwargs)

    return [
        rel
        for rel in self.relationships
        if rel.relationship_type == RelationshipType.HAS_ACCESS_OWNER
    ]

get_stats async

get_stats(
    return_raw: bool = False,
    *,
    context: RouteContext | None = None,
    **context_kwargs
) -> dict | Any

Get file type counts and index status for the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
async def get_stats(
    self,
    return_raw: bool = False,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> dict | Any:
    """Get file type counts and index status for the fileset."""
    context = RouteContext.build_context(context=context, **context_kwargs)

    res = await fileset_routes.get_fileset_stats(
        auth=self.auth,
        fileset_id=self.parent_id,
        context=context,
    )

    if return_raw:
        return res

    return res.response

remove_owners async

remove_owners(**_kwargs) -> bool

Remove owners from the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
198
199
200
201
202
203
204
205
async def remove_owners(
    self,
    **_kwargs,
) -> bool:
    """Remove owners from the fileset."""
    raise NotImplementedError(
        "Removing fileset owners is not supported by the Domo API."
    )

remove_relationship async

remove_relationship(
    target_entity_id: str,
    target_entity_type: EntityType,
    relationship_type: RelationshipType,
    **kwargs
) -> bool

Remove an access relationship for the fileset.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
59
60
61
62
63
64
65
66
67
68
69
async def remove_relationship(
    self,
    target_entity_id: str,
    target_entity_type: EntityType,
    relationship_type: RelationshipType,
    **kwargs,
) -> bool:
    """Remove an access relationship for the fileset."""
    raise NotImplementedError(
        "Removing fileset access entries is not supported by the Domo API."
    )

share async

share(
    user_ids: list[int] | None = None,
    group_ids: list[int] | None = None,
    *,
    context: RouteContext | None = None,
    **context_kwargs
) -> bool

Share the fileset with users or groups (READ access only).

Note: The Domo fileset API only supports 'READ' as a non-owner permission. Owner permission cannot be modified via the access endpoint.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
async def share(
    self,
    user_ids: list[int] | None = None,
    group_ids: list[int] | None = None,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> bool:
    """Share the fileset with users or groups (READ access only).

    Note: The Domo fileset API only supports 'READ' as a non-owner permission.
    Owner permission cannot be modified via the access endpoint.
    """
    context = RouteContext.build_context(context=context, **context_kwargs)

    access_entries = []
    for uid in user_ids or []:
        access_entries.append(
            {"entityId": uid, "entityType": "USER", "permission": "READ"}
        )
    for gid in group_ids or []:
        access_entries.append(
            {"entityId": gid, "entityType": "GROUP", "permission": "READ"}
        )

    if not access_entries:
        raise ValueError("Must provide user_ids or group_ids to share fileset")

    body = {"fileSetAccess": access_entries}

    res = await fileset_routes.share_fileset(
        auth=self.auth,
        fileset_id=self.parent_id,
        body=body,
        context=context,
    )

    # Invalidate cache so next access fetches fresh data
    self.invalidate_cache()
    return res.is_success

transfer_owner async

transfer_owner(
    user_id: int,
    *,
    context: RouteContext | None = None,
    **context_kwargs
) -> bool

TRANSFER ownership of the fileset to user_id.

This is not an "add". It calls transfer_fileset_ownership, which moves the fileset's owner — and remove_owners raises NotImplementedError, so there is no undo through this library.

⚠️ The access list will not show you that this happened. Verified on domo-community 2026-08-31 with a throwaway fileset: after the call the fileset's scalar owner had moved from the caller to user_id, but get_fileset_access listed BOTH principals with permission OWNER. Read back get_fileset_by_id(...).response["owner"], not the access list, to see who owns it now — checking the ACL makes a transfer look additive.

Named add_owners until it was renamed; add_owners remains as a deprecated alias. The old name shared a spelling with DomoCardAccessController.add_owners and DomoPageAccessController.add_owners, which really are additive, so the same call read as safe on three controllers and was destructive on one.

See .agents/guides/access-and-sharing.md.

Source code in src/crew_dcs/classes/DomoFileset/access_controller.py
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
async def transfer_owner(
    self,
    user_id: int,
    *,
    context: RouteContext | None = None,
    **context_kwargs,
) -> bool:
    """TRANSFER ownership of the fileset to `user_id`.

    This is not an "add". It calls `transfer_fileset_ownership`, which moves
    the fileset's `owner` — and `remove_owners` raises NotImplementedError,
    so there is no undo through this library.

    ⚠️ **The access list will not show you that this happened.** Verified on
    domo-community 2026-08-31 with a throwaway fileset: after the call the
    fileset's scalar `owner` had moved from the caller to `user_id`, but
    `get_fileset_access` listed BOTH principals with permission OWNER. Read
    back `get_fileset_by_id(...).response["owner"]`, not the access list, to
    see who owns it now — checking the ACL makes a transfer look additive.

    Named `add_owners` until it was renamed; `add_owners` remains as a
    deprecated alias. The old name shared a spelling with
    `DomoCardAccessController.add_owners` and
    `DomoPageAccessController.add_owners`, which really are additive, so the
    same call read as safe on three controllers and was destructive on one.

    See `.agents/guides/access-and-sharing.md`.
    """
    context = RouteContext.build_context(context=context, **context_kwargs)

    res = await fileset_routes.transfer_fileset_ownership(
        auth=self.auth,
        fileset_id=self.parent_id,
        user_id=user_id,
        context=context,
    )

    # Invalidate cache so next access fetches fresh data
    self.invalidate_cache()
    return res.is_success