Skip to content

feat(python): expose Permissions and remaining user auth methods - #3727

Open
ethanlin01x wants to merge 14 commits into
apache:masterfrom
ethanlin01x:feat/python-permissions
Open

feat(python): expose Permissions and remaining user auth methods#3727
ethanlin01x wants to merge 14 commits into
apache:masterfrom
ethanlin01x:feat/python-permissions

Conversation

@ethanlin01x

Copy link
Copy Markdown
Contributor

Which issue does this PR address?

Closes #3726

Rationale

The Python SDK could create users but not grant them access to anything: create_user hardcoded None for permissions, and update_permissions, change_password, and logout_user` were unexposed.

What changed?

Before, the Python SDK could create users but not grant them access to anything: create_user hardcoded None for permissions, and update_permissions, change_password, and logout_user were unexposed.
Now the Rust Permissions hierarchy is mirrored as PyO3 classes, create_user takes an optional permissions argument, UserInfoDetails exposes a permissions getter, and the three missing methods complete the UserClient surface, with the underlying Rust client handling the wire encoding.

Local Execution

  • Passed
  • Pre-commit hooks ran

AI Usage

Claude was used to help generate and review this PR and all the changes are checked by the human.

@ethanlin01x
ethanlin01x force-pushed the feat/python-permissions branch 2 times, most recently from 63a8908 to 84a9f3b Compare July 21, 2026 16:05
Mirror the Rust Permissions, GlobalPermissions, StreamPermissions, and
TopicPermissions types as PyO3 classes so user permissions can be built
and inspected from Python. Stream and topic dict keys are typed u32 to
match the wire format, so out-of-range IDs fail at construction instead
of being silently truncated. The client methods that consume these
classes follow in the next commits.
create_user hardcoded None for permissions, so every user came out
unprivileged and UserInfoDetails gave no way to inspect grants. Wire the
Permissions argument through create_user and add the permissions getter
so grants round-trip through get_user. The credential helpers shared by
the user tests move to tests/utils.py for the new enforcement tests.
Permissions set at creation were frozen: there was no way to grant,
replace, or revoke them afterwards. update_permissions is a full
replacement and None clears the permissions entirely, matching the Rust
client semantics.
Password rotation required deleting and recreating the user, losing its
id and permissions. change_password verifies the current password
server-side, and a user can rotate its own credentials without any admin
permission.
Sessions could only be abandoned by dropping the connection, leaving the
server-side session authenticated until the socket closed. logout_user
ends the session explicitly; a later login_user on the same client
starts a fresh one.
@ethanlin01x
ethanlin01x force-pushed the feat/python-permissions branch from 84a9f3b to 22bc32c Compare July 21, 2026 16:11
@codecov

codecov Bot commented Jul 21, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.70782% with 8 lines in your changes missing coverage. Please review.
✅ Project coverage is 75.04%. Comparing base (f67f038) to head (1e31681).

Files with missing lines Patch % Lines
foreign/python/src/permissions.rs 95.67% 8 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##             master    #3727      +/-   ##
============================================
- Coverage     75.10%   75.04%   -0.06%     
  Complexity      969      969              
============================================
  Files          1307     1308       +1     
  Lines        152751   152934     +183     
  Branches     128185   128126      -59     
============================================
+ Hits         114726   114775      +49     
- Misses        34494    34633     +139     
+ Partials       3531     3526       -5     
Components Coverage Δ
Rust Core 75.40% <ø> (-0.12%) ⬇️
Java SDK 62.71% <ø> (ø)
C# SDK 72.26% <ø> (ø)
Python SDK 93.10% <96.70%> (+0.82%) ⬆️
PHP SDK 84.52% <ø> (ø)
Node SDK 92.24% <ø> (+0.12%) ⬆️
Go SDK 43.08% <ø> (ø)
Files with missing lines Coverage Δ
foreign/python/src/client.rs 99.21% <100.00%> (+0.06%) ⬆️
foreign/python/src/lib.rs 100.00% <100.00%> (ø)
foreign/python/src/user.rs 80.43% <100.00%> (+1.36%) ⬆️
foreign/python/src/permissions.rs 95.67% <95.67%> (ø)

... and 14 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ethanlin01x
ethanlin01x marked this pull request as ready for review July 21, 2026 16:23
@ethanlin01x

Copy link
Copy Markdown
Contributor Author

/ready

@github-actions github-actions Bot added the S-waiting-on-review PR is waiting on a reviewer label Jul 21, 2026

@slbotbm slbotbm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

first round

Comment thread foreign/python/src/permissions.rs Outdated
Comment thread foreign/python/tests/test_permissions.py
Comment thread foreign/python/tests/test_permissions.py Outdated
@github-actions github-actions Bot added S-waiting-on-author PR is waiting on author response and removed S-waiting-on-review PR is waiting on a reviewer labels Jul 23, 2026
@ethanlin01x
ethanlin01x requested a review from slbotbm July 23, 2026 15:56
@ethanlin01x

Copy link
Copy Markdown
Contributor Author

/ready

@github-actions github-actions Bot added S-waiting-on-review PR is waiting on a reviewer and removed S-waiting-on-author PR is waiting on author response labels Jul 23, 2026
Comment thread foreign/python/tests/test_permissions.py
Comment thread foreign/python/src/client.rs Outdated
Comment thread foreign/python/src/permissions.rs
Comment thread foreign/python/src/permissions.rs
@github-actions github-actions Bot added S-waiting-on-author PR is waiting on author response and removed S-waiting-on-review PR is waiting on a reviewer labels Jul 26, 2026
The trailing underscore avoided the Python keyword collision but reads
poorly at call sites. Reviewer settled on the explicit long name.
@ethanlin01x
ethanlin01x requested a review from slbotbm July 26, 2026 10:10
@ethanlin01x

Copy link
Copy Markdown
Contributor Author

/ready

@github-actions github-actions Bot added S-waiting-on-review PR is waiting on a reviewer and removed S-waiting-on-author PR is waiting on author response labels Jul 26, 2026
@ethanlin01x
ethanlin01x force-pushed the feat/python-permissions branch from 62507bf to e1f5e2e Compare July 26, 2026 10:11
The wire format encodes an empty streams or topics map identically to
an absent one, so a Permissions(streams={}) fetched back from the
server compared unequal to what was stored. Collapse empty maps to
None at construction to keep round-trip equality.
update_permissions defaulted permissions to None, so forgetting the
argument silently wiped a user's permissions; clearing now requires an
explicit None. The permission constructors accepted up to ten adjacent
positional booleans, where a shifted argument grants the wrong
privilege without any error; the flags are now keyword-only.
The flag docs only stated same-level inclusion, hiding that read and
manage flags cascade down to message operations: read_topics permits
polling message contents, manage_topics permits polling and sending,
and manage_streams inherits both through manage_topics. Document the
direct inclusion edges per the server permissioner rules, note that
they apply transitively, and spell out the grants hidden behind read
flags: consumer group management under read_topics and consumer
offset management under poll_messages.
A user with manage_users can change another user's password; a user
without it is denied and the target's old password remains valid.
@ethanlin01x
ethanlin01x force-pushed the feat/python-permissions branch from e1f5e2e to 364162a Compare July 26, 2026 11:33
@ethanlin01x

Copy link
Copy Markdown
Contributor Author

/ready

@ethanlin01x

Copy link
Copy Markdown
Contributor Author

/request-review @spetz

@github-actions
github-actions Bot requested a review from spetz July 30, 2026 05:05
@ethanlin01x

Copy link
Copy Markdown
Contributor Author

Hi @spetz

Would you mind taking a look at this PR when you get a chance?
Since you helped merge my previous Python PR, I’d really appreciate your eyes on this one as well. Please feel free to leave any comments or suggestions.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-review PR is waiting on a reviewer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[python sdk] Expose Permissions and the remaining user auth methods

2 participants