Azure Data Explorer RLS策略报错:合规操作符仍提示summarize被阻止
问题
在Azure Data Explorer(ADX)中为已摄入数据实现行级安全(RLS)时,创建了RLS策略函数RestrictAccess,AccessTable结构及数据如下。执行RLS启用命令后,明明只使用了允许的操作符,却收到summarize操作被阻止的错误,请问问题出在哪里?
策略函数代码:
table(TableName) | join kind=leftsemi ( AccessTable | extend current_member=case( current_principal_is_member_of('aadgroup=00000000-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'foo', current_principal_is_member_of('aadgroup=11111111-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'bar', current_principal_is_member_of('aadgroup=22222222-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'baz', 'unknown' ) | where current_member == groupName | distinct deviceId ) on deviceId }
AccessTable定义:
datatable(deviceId: string, groupName: string)[ 'A0000000-1111-2222-3333-444444444444', 'foo', 'B0000000-1111-2222-3333-444444444444', 'foo', 'B0000000-1111-2222-3333-444444444444', 'bar', 'D0000000-1111-2222-3333-444444444444', 'baz' ];
执行的策略命令:
收到的错误信息:
Error during execution of a policy operation: Error in row_level_security query for database("MyDatabase").table("MyTable"): the following operators were blocked: 'summarize' (only the following operators are allowed: 'as', 'distinct', 'extend', 'join', 'limit', 'project', 'project-away', 'project-keep', 'project-rename', 'project-reorder', 'union', 'where')
原因分析
ADX的RLS策略执行逻辑中,distinct操作符会被底层转换为summarize by操作,而summarize不在RLS允许的操作符列表内,因此触发了阻止错误。虽然你显式使用的是允许的distinct,但底层转换后的summarize违反了策略限制。
解决方案
将函数中的distinct deviceId替换为通过in子查询过滤的方式,避免触发底层summarize转换,修改后的函数如下:
let allowedDevices = AccessTable | extend current_member=case( current_principal_is_member_of('aadgroup=00000000-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'foo', current_principal_is_member_of('aadgroup=11111111-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'bar', current_principal_is_member_of('aadgroup=22222222-BBBB-CCCC-DDDD-EEEEEEEEEEEE'), 'baz', 'unknown' ) | where current_member == groupName | project deviceId; table(TableName) | where deviceId in (allowedDevices) }
修改后重新执行RLS启用命令即可正常生效,该方式通过in子查询筛选允许访问的deviceId,全程使用RLS允许的操作符。
内容的提问来源于stack exchange,提问作者Dammi
相关产品推荐
相关产品推荐

