pdp
pdp ¶
PDP (Personalized Data Permissions) Route Functions
This module provides functions for managing Domo PDP policies including retrieval, creation, updating, and deletion operations. PDP policies control data access at the row level based on user, group, or virtual user assignments.
Submodules
exceptions: Exception classes for PDP operations core: Core retrieval and utility functions crud: Create, update, delete, and toggle operations
Exception Classes
PDP_GET_Error: Raised when PDP policy retrieval fails SearchPDPNotFoundError: Raised when PDP policy search returns no results PDP_CRUD_Error: Raised when PDP policy create/update/delete operations fail
Core Functions
get_pdp_policies: Retrieve all PDP policies for a dataset search_pdp_policies_by_name: Search for specific PDP policies by name generate_policy_parameter_simple: Utility function for creating policy parameters generate_policy_body: Utility function for creating policy request bodies
CRUD Functions
create_policy: Create a new PDP policy update_policy: Update an existing PDP policy delete_policy: Delete a PDP policy toggle_pdp: Enable or disable PDP for a dataset
PDP_CRUD_Error ¶
PDP_CRUD_Error(
operation: str,
dataset_id: str | None = None,
policy_id: str | None = None,
res: ResponseGetData | None = None,
message: str | None = None,
**kwargs
)
Bases: RouteError
Raised when PDP policy create, update, or delete operations fail.
This exception is used for failures during policy creation, modification, or deletion operations.
Source code in src/crew_dcs/routes/pdp/exceptions.py
81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 | |
PDP_GET_Error ¶
PDP_GET_Error(
dataset_id: str | None = None,
res: ResponseGetData | None = None,
message: str | None = None,
**kwargs
)
Bases: RouteError
Raised when PDP policy retrieval operations fail.
This exception is used for failures during GET operations on PDP policies, including API errors and unexpected response formats.
Source code in src/crew_dcs/routes/pdp/exceptions.py
35 36 37 38 39 40 41 42 43 44 45 46 47 48 | |
SearchPDPNotFoundError ¶
SearchPDPNotFoundError(
search_criteria: str,
res: ResponseGetData | None = None,
**kwargs
)
Bases: RouteError
Raised when PDP policy search operations return no results.
This exception is used when searching for specific PDP policies that don't exist or when search criteria match no policies.
Source code in src/crew_dcs/routes/pdp/exceptions.py
59 60 61 62 63 64 65 66 67 68 69 70 | |
create_policy
async
¶
create_policy(
auth: DomoAuth,
dataset_id: str,
body: dict,
override_same_name: bool = False,
is_suppress_errors: bool = False,
return_raw: bool = False,
*,
context: RouteContext | None = None,
**context_kwargs
) -> ResponseGetData
Create a new PDP policy for a dataset.
Creates a new Personalized Data Permissions policy with the specified parameters and assignments. Can check for duplicate policy names before creating.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
DomoAuth
|
Authentication object containing instance and credentials |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
body
|
dict
|
Policy request body (from generate_policy_body) |
required |
override_same_name
|
bool
|
If True, allow creating policy with duplicate name |
False
|
is_suppress_errors
|
bool
|
If True, return existing policy instead of error for duplicates |
False
|
return_raw
|
bool
|
Return raw API response without processing |
False
|
context
|
RouteContext | None
|
Optional RouteContext for request configuration |
None
|
**context_kwargs
|
Additional context parameters (session, debug_api, etc.) |
{}
|
Returns:
| Type | Description |
|---|---|
ResponseGetData
|
ResponseGetData object containing created policy information |
Raises:
| Type | Description |
|---|---|
PDP_CRUD_Error
|
If policy creation fails or duplicate name exists |
Example
params = [generate_policy_parameter_simple("Region", column_values_ls=["West"])] body = generate_policy_body( ... policy_name="West Region Access", ... dataset_id="abc123", ... parameters_ls=params ... ) response = await create_policy(auth, "abc123", body) policy_id = response.response.get("filterGroupId")
Source code in src/crew_dcs/routes/pdp/crud.py
38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 | |
delete_policy
async
¶
delete_policy(
auth: DomoAuth,
dataset_id: str,
policy_id: str,
return_raw: bool = False,
*,
context: RouteContext | None = None,
**context_kwargs
) -> ResponseGetData
Delete a PDP policy.
Permanently removes a Personalized Data Permissions policy from a dataset. This action cannot be undone.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
DomoAuth
|
Authentication object containing instance and credentials |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
policy_id
|
str
|
Unique identifier for the policy to delete |
required |
return_raw
|
bool
|
Return raw API response without processing |
False
|
context
|
RouteContext | None
|
Optional RouteContext for request configuration |
None
|
**context_kwargs
|
Additional context parameters (session, debug_api, etc.) |
{}
|
Returns:
| Type | Description |
|---|---|
ResponseGetData
|
ResponseGetData object with confirmation message |
Raises:
| Type | Description |
|---|---|
PDP_CRUD_Error
|
If policy deletion fails |
Example
response = await delete_policy(auth, "abc123", "policy123") print(f"Policy deleted: {response.response}")
Source code in src/crew_dcs/routes/pdp/crud.py
217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 | |
generate_policy_body ¶
generate_policy_body(
policy_name: str,
dataset_id: str,
parameters_ls: list[dict],
policy_id: str | None = None,
user_ids: list[str] | None = None,
group_ids: list[str] | None = None,
virtual_user_ids: list[str] | None = None,
) -> dict
Generate a policy body for PDP policy creation or update.
Creates a complete request body for creating or updating a PDP policy, including filter parameters and user/group assignments.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
policy_name
|
str
|
Name for the policy |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
parameters_ls
|
list[dict]
|
list of parameter dicts (from generate_policy_parameter_simple) |
required |
policy_id
|
str | None
|
Policy ID (only for updates, omit for new policies) |
None
|
user_ids
|
list[str] | None
|
list of user IDs to assign the policy to |
None
|
group_ids
|
list[str] | None
|
list of group IDs to assign the policy to |
None
|
virtual_user_ids
|
list[str] | None
|
list of virtual user IDs to assign the policy to |
None
|
Returns:
| Type | Description |
|---|---|
dict
|
Dictionary representing complete policy request body |
Example
params = [generate_policy_parameter_simple("Region", column_values_ls=["West"])] body = generate_policy_body( ... policy_name="West Region Access", ... dataset_id="abc123", ... parameters_ls=params, ... user_ids=["12345"] ... )
Use body in create_policy or update_policy¶
Source code in src/crew_dcs/routes/pdp/core.py
203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 | |
generate_policy_parameter_simple ¶
generate_policy_parameter_simple(
column_name: str,
type: str = "COLUMN",
column_values_ls: list[str] | None = None,
operator: str = "EQUALS",
ignore_case: bool = True,
) -> dict
Generate a simple policy parameter for PDP policy creation.
Creates a parameter dictionary that defines a filter condition for a PDP policy. Parameters specify which column values users can see.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
column_name
|
str
|
Name of the column to filter on |
required |
type
|
str
|
Parameter type (default: "COLUMN") |
'COLUMN'
|
column_values_ls
|
list[str] | None
|
list of column values to filter, or single value |
None
|
operator
|
str
|
Comparison operator (default: "EQUALS") |
'EQUALS'
|
ignore_case
|
bool
|
Whether to ignore case when comparing values (default: True) |
True
|
Returns:
| Type | Description |
|---|---|
dict
|
Dictionary representing a policy parameter |
Example
param = generate_policy_parameter_simple( ... column_name="Region", ... column_values_ls=["West", "East"] ... ) print(param) {'type': 'COLUMN', 'name': 'Region', 'values': ['West', 'East'], ...}
Source code in src/crew_dcs/routes/pdp/core.py
160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 | |
get_pdp_policies
async
¶
get_pdp_policies(
auth: DomoAuth,
dataset_id: str,
include_all_rows: bool = True,
return_raw: bool = False,
*,
context: RouteContext | None = None,
**context_kwargs
) -> ResponseGetData
Retrieve all PDP policies for a specific dataset.
Fetches a list of all PDP (Personalized Data Permissions) policies associated with the specified dataset. Includes policy filters, associations, and open policy settings when include_all_rows is True.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
DomoAuth
|
Authentication object containing instance and credentials |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
include_all_rows
|
bool
|
Include policy associations, filters, and open policy (default: True) |
True
|
return_raw
|
bool
|
Return raw API response without processing |
False
|
context
|
RouteContext | None
|
Optional RouteContext for request configuration |
None
|
**context_kwargs
|
Additional context parameters (session, debug_api, etc.) |
{}
|
Returns:
| Type | Description |
|---|---|
ResponseGetData
|
ResponseGetData object containing list of PDP policies |
Raises:
| Type | Description |
|---|---|
PDP_GET_Error
|
If PDP policy retrieval fails or API returns an error |
Example
policies_response = await get_pdp_policies(auth, "abc123") for policy in policies_response.response: ... print(f"Policy: {policy['name']}, ID: {policy['filterGroupId']}")
Source code in src/crew_dcs/routes/pdp/core.py
38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 | |
search_pdp_policies_by_name ¶
search_pdp_policies_by_name(
search_name: str,
result_list: list[dict],
is_exact_match: bool = True,
is_suppress_errors: bool = False,
) -> dict | list[dict | bool]
Search for PDP policies by name within a list of policies.
Searches through a list of PDP policies to find those matching the specified name. Can perform exact or partial matching.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
search_name
|
str
|
Name or partial name to search for |
required |
result_list
|
list[dict]
|
list of policy dictionaries from get_pdp_policies response |
required |
is_exact_match
|
bool
|
If True, search for exact name match; if False, partial match |
True
|
is_suppress_errors
|
bool
|
If True, return False instead of raising error when not found |
False
|
Returns:
| Type | Description |
|---|---|
dict | list[dict | bool]
|
Single policy dict (exact match), list of policy dicts (partial match), |
dict | list[dict | bool]
|
or False if no matches and is_suppress_errors is True |
Raises:
| Type | Description |
|---|---|
SearchPDPNotFoundError
|
If no policies match the search criteria (unless is_suppress_errors is True) |
Example
policies = await get_pdp_policies(auth, "abc123") policy = search_pdp_policies_by_name("Sales Policy", policies.response) print(f"Found policy: {policy['filterGroupId']}")
Source code in src/crew_dcs/routes/pdp/core.py
111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 | |
toggle_pdp
async
¶
toggle_pdp(
auth: DomoAuth,
dataset_id: str,
is_enable: bool = True,
return_raw: bool = False,
*,
context: RouteContext | None = None,
**context_kwargs
) -> ResponseGetData
Enable or disable PDP for a dataset.
Toggles Personalized Data Permissions on or off for the specified dataset. When disabled, all users can see all data in the dataset.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
DomoAuth
|
Authentication object containing instance and credentials |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
is_enable
|
bool
|
If True, enable PDP; if False, disable PDP (default: True) |
True
|
return_raw
|
bool
|
Return raw API response without processing |
False
|
context
|
RouteContext | None
|
Optional RouteContext for request configuration |
None
|
**context_kwargs
|
Additional context parameters (session, debug_api, etc.) |
{}
|
Returns:
| Type | Description |
|---|---|
ResponseGetData
|
ResponseGetData object with confirmation message |
Raises:
| Type | Description |
|---|---|
PDP_CRUD_Error
|
If toggle operation fails |
Example
Enable PDP for a dataset¶
response = await toggle_pdp(auth, "abc123", is_enable=True)
Disable PDP for a dataset¶
response = await toggle_pdp(auth, "abc123", is_enable=False)
Source code in src/crew_dcs/routes/pdp/crud.py
284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 | |
update_policy
async
¶
update_policy(
auth: DomoAuth,
dataset_id: str,
policy_id: str,
body: dict,
return_raw: bool = False,
*,
context: RouteContext | None = None,
**context_kwargs
) -> ResponseGetData
Update an existing PDP policy.
Modifies an existing Personalized Data Permissions policy with new parameters, assignments, or name.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
DomoAuth
|
Authentication object containing instance and credentials |
required |
dataset_id
|
str
|
Unique identifier for the dataset |
required |
policy_id
|
str
|
Unique identifier for the policy to update |
required |
body
|
dict
|
Policy request body (from generate_policy_body) |
required |
return_raw
|
bool
|
Return raw API response without processing |
False
|
context
|
RouteContext | None
|
Optional RouteContext for request configuration |
None
|
**context_kwargs
|
Additional context parameters (session, debug_api, etc.) |
{}
|
Returns:
| Type | Description |
|---|---|
ResponseGetData
|
ResponseGetData object containing updated policy information |
Raises:
| Type | Description |
|---|---|
PDP_CRUD_Error
|
If policy update fails |
Example
params = [generate_policy_parameter_simple("Region", column_values_ls=["West", "East"])] body = generate_policy_body( ... policy_name="Updated Policy Name", ... dataset_id="abc123", ... parameters_ls=params, ... policy_id="policy123" ... ) response = await update_policy(auth, "abc123", "policy123", body)
Source code in src/crew_dcs/routes/pdp/crud.py
141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 | |