0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Pythonでアクセス権限を確認、直付けを消しても残る2件

0
Posted at

直付けのアクセス権限を外せば、閲覧だけに戻りますか? 役割経由で2件残りました。棚卸し表には付与元が必要です。

今日、僕はPythonで編集権限の直付けを消しました。編集と共有は残ったまま。

Pythonでアクセス権限の付与元を出す

直接と役割の許可を足す例です。readは閲覧、writeは編集、shareは共有。必要なのは閲覧だけ。拒否ルールやフォルダ継承は対象外です。

Python 3.14.6で確認済み。audit_access.pyに保存し、python3 audit_access.pyで実行。

roles = {'reader': {'read'}, 'editor': {'read', 'write', 'share'}}
allowed = {'read'}

def audit(direct, role):
    sources = {'direct': direct, role: roles[role]}
    effective = set().union(*sources.values())
    extra = effective - allowed
    print(f'過剰: {len(extra)}件')
    for action in sorted(extra):
        origin = ','.join(k for k, v in sources.items() if action in v)
        print(f'{action}: {origin}')
    return extra

audit({'write'}, 'editor')
audit(set(), 'editor')
audit(set(), 'reader')

出力です。

過剰: 2件
share: editor
write: direct,editor
過剰: 2件
share: editor
write: editor
過剰: 0件

unionで許可を集め、- allowedで余分な権限を抽出。集合では同じwriteを2か所から付けても1件です。直付けを消してもeditor側に残ります。

変更依頼までつなぐ

readerへ変えると0件。付与元が出れば、管理担当への変更依頼も具体になります。ここ地味に効きます。

ChatGPTには匿名のIDと結果を渡し、依頼文を整えます。

userAはreadだけ必要。直付けなし、所属editor。
editorはread/write/share、readerはread。
userAをreaderへ移す依頼文と変更後の確認項目を作って。
共通の役割定義は保つ。承認済みとは書かないで。

役割名の誤記はKeyErrorで停止しました。空の権限として通すと見逃します。英字順だと共有が編集より先に出ますね。

棚卸しで残すのは、余分な権限と付与元の組。共通のeditor定義を削ると、ほかの所属者にも影響します。この例の候補はuserAをreaderへ移すこと。申請には移動後の権限がreadだけになる確認を添えます。

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?