1### Workflow to grant read (SELECT) privilege to all users in NSAPH admin role
2# Copyright (c) 2022. Harvard University
3#
4# Developed by Research Software Engineering,
5# Faculty of Arts and Sciences, Research Computing (FAS RC)
6# Author: Michael A Bouzinier
7#
8# Licensed under the Apache License, Version 2.0 (the "License");
9# you may not use this file except in compliance with the License.
10# You may obtain a copy of the License at
11#
12# http://www.apache.org/licenses/LICENSE-2.0
13#
14# Unless required by applicable law or agreed to in writing, software
15# distributed under the License is distributed on an "AS IS" BASIS,
16# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17# See the License for the specific language governing permissions and
18# limitations under the License.
19#
20
21cwlVersion: v1.2
22class: Workflow
23requirements:
24 InlineJavascriptRequirement: {}
25 StepInputExpressionRequirement: {}
26
27doc: |
28 This workflow executes an SQL statement in the database to
29 This is a wrapper around the tool to be called from Airflow DAG.
30
31inputs:
32 database:
33 type: File
34 doc: Path to database connection file, usually database.ini
35 connection_name:
36 type: string
37 doc: The name of the section in the database.ini file
38 owner:
39 type: string
40 default: nsaph_admin
41
42steps:
43 grant:
44 run: alter_database.cwl
45 doc: |
46 Grants read access to the members of NSAPH group for newly created
47 or updated tables
48 in:
49 database: database
50 connection_name: connection_name
51 sql:
52 valueFrom: $(["CALL public.owner_to('" + inputs.owner + "');"])
53 owner: owner
54 out:
55 - log
56 - err
57
58
59outputs:
60 grant_log:
61 type: File
62 outputSource: grant/log
63 grant_err:
64 type: File
65 outputSource: grant/err