v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-1342224376.9 KB
rowAccessPolicies

Creates a row access policy. # IAM Permissions Requires the following IAM permission(s) on the table: - bigquery.rowAccessPolicies.create - bigquery.rowAccessPolicies.setIamPolicy - bigquery.tables.getData

post/projects/{+projectId}/datasets/{+datasetId}/tables/{+tableId}/rowAccessPolicies

Path parameters

projectIdstring required

Required. Project ID of the table to get the row access policy.

datasetIdstring required

Required. Dataset ID of the table to get the row access policy.

tableIdstring required

Required. Table ID of the table to get the row access policy.

Request body

filterPredicatestring

Required. A SQL boolean expression that represents the rows defined by this row access policy, similar to the boolean expression in a WHERE clause of a SELECT query on a table. References to other tables, routines, and temporary functions are not supported. Examples: region="EU" date_field = CAST('2019-9-27' as DATE) nullable_field is not NULL numeric_field BETWEEN 1.0 AND 5.0

granteesstring[]

Optional. Input only. The optional list of iam_member users or groups that specifies the initial members that the row-level access policy should be created with. grantees types: - "user:alice@example.com": An email address that represents a specific Google account. - "serviceAccount:my-other-app@appspot.gserviceaccount.com": An email address that represents a service account. - "group:admins@example.com": An email address that represents a Google group. - "domain:example.com":The Google Workspace domain (primary) that represents all the users of that domain. - "allAuthenticatedUsers": A special identifier that represents all service accounts and all users on the internet who have authenticated with a Google Account. This identifier includes accounts that aren't connected to a Google Workspace or Cloud Identity domain, such as personal Gmail accounts. Users who aren't authenticated, such as anonymous visitors, aren't included. - "allUsers":A special identifier that represents anyone who is on the internet, including authenticated and unauthenticated users. Because BigQuery requires authentication before a user can access the service, allUsers includes only authenticated users.

etagstring

Output only. A hash of this resource.

lastModifiedTimestring google-datetime

Output only. The time when this row access policy was last modified, in milliseconds since the epoch.

creationTimestring google-datetime

Output only. The time when this row access policy was created, in milliseconds since the epoch.

Response

Successful response