Created
May 11, 2026 22:30
-
-
Save philerooski/54cfa864c359f85f8de4e81056c68754 to your computer and use it in GitHub Desktop.
Snowflake test script: set default secondary roles by analyst rules
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| USE ROLE USERADMIN; | |
| -- Copied from admin/users.sql lines 165-254 for isolated testing. | |
| -- Set DEFAULT_SECONDARY_ROLES based on user type and role access. | |
| -- A user is treated as an analyst if ALL of the following are true: | |
| -- 1) user type is not SERVICE | |
| -- 2) user name does not contain 'service' (case-insensitive) | |
| -- 3) user is not granted any of these roles: | |
| -- DATA_ENGINEER, ACCOUNTADMIN, SYSADMIN, SECURITYADMIN, USERADMIN | |
| -- Analysts get DEFAULT_SECONDARY_ROLES=('ALL'). | |
| -- Non-analysts (any user failing one or more checks above) get | |
| -- DEFAULT_SECONDARY_ROLES=(). | |
| EXECUTE IMMEDIATE $$ | |
| DECLARE | |
| updated_users ARRAY DEFAULT ARRAY_CONSTRUCT(); -- users we updated | |
| username STRING; -- a user identifier | |
| user_type STRING; -- user type from SHOW USERS | |
| dsr_value STRING; -- default secondary role setting | |
| normalized_dsr_value STRING; -- normalized default secondary role setting | |
| role_name STRING; -- role granted to a user | |
| is_service_user BOOLEAN; -- service users are excluded | |
| is_excluded_by_role BOOLEAN; -- developers/admins are excluded | |
| should_enable_all BOOLEAN; -- whether user should receive ['ALL'] | |
| user_cursor CURSOR FOR | |
| SELECT "name", "type", "default_secondary_roles" | |
| FROM TABLE(RESULT_SCAN(LAST_QUERY_ID())) | |
| WHERE "name" <> 'SNOWFLAKE' | |
| AND UPPER("name") NOT IN ( | |
| 'JOE.SMITH@SAGEBASE.ORG', | |
| 'JONI.HARKER@SAGEBASE.ORG' | |
| ); -- Jumpcloud-managed users | |
| role_cursor CURSOR FOR | |
| SELECT "name" | |
| FROM TABLE(RESULT_SCAN(LAST_QUERY_ID())) | |
| WHERE "granted_on" = 'ROLE'; -- A cursor over roles granted to a user | |
| BEGIN | |
| SHOW USERS; | |
| OPEN user_cursor; | |
| LOOP | |
| -- Iterate through every user returned by SHOW USERS. | |
| FETCH user_cursor INTO username, user_type, dsr_value; | |
| -- exit condition | |
| IF (username IS NULL) THEN | |
| BREAK; | |
| END IF; | |
| LET quoted_username STRING := '"' || :username || '"'; | |
| -- Normalize current value so comparisons work across formatting variants. | |
| normalized_dsr_value := UPPER(COALESCE(dsr_value, '')); | |
| -- Service users are excluded by explicit type and by service-like username. | |
| is_service_user := (UPPER(COALESCE(user_type, '')) = 'SERVICE') | |
| OR (POSITION('service' IN LOWER(username)) > 0); | |
| is_excluded_by_role := FALSE; | |
| -- Inspect role grants for this user to detect developer/admin exclusions. | |
| EXECUTE IMMEDIATE | |
| 'SHOW GRANTS TO USER IDENTIFIER(''' || :quoted_username || ''')'; | |
| OPEN role_cursor; | |
| LOOP | |
| -- Walk granted roles until we find an excluded role or exhaust results. | |
| FETCH role_cursor INTO role_name; | |
| IF (role_name IS NULL) THEN | |
| BREAK; | |
| END IF; | |
| IF (role_name IN ('DATA_ENGINEER', 'ACCOUNTADMIN', 'SYSADMIN', 'SECURITYADMIN', 'USERADMIN')) THEN | |
| -- Any matching role disqualifies the user from analyst treatment. | |
| is_excluded_by_role := TRUE; | |
| BREAK; | |
| END IF; | |
| END LOOP; | |
| CLOSE role_cursor; | |
| -- Only non-service users without excluded roles are treated as analysts. | |
| should_enable_all := (NOT is_service_user) AND (NOT is_excluded_by_role); | |
| IF (should_enable_all) THEN | |
| IF (normalized_dsr_value NOT IN ('[\'ALL\']', '["ALL"]')) THEN | |
| -- Enable automatic use of all granted secondary roles for analysts. | |
| ALTER USER IDENTIFIER(:quoted_username) SET DEFAULT_SECONDARY_ROLES=('ALL'); | |
| updated_users := ARRAY_APPEND(updated_users, username); | |
| END IF; | |
| ELSE | |
| IF (normalized_dsr_value != '[]') THEN | |
| -- Enforce no default secondary roles for excluded users. | |
| ALTER USER IDENTIFIER(:quoted_username) SET DEFAULT_SECONDARY_ROLES=(); | |
| updated_users := ARRAY_APPEND(updated_users, username); | |
| END IF; | |
| END IF; | |
| END LOOP; | |
| CLOSE user_cursor; | |
| RETURN updated_users; | |
| END; | |
| $$; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment