*: add document for column-level masking policy feature#22613
*: add document for column-level masking policy feature#22613tiancaiamao wants to merge 15 commits into
Conversation
… Grafana This commit addresses issue #21768 by adding a new section to document the default login credentials for TiDB Dashboard and Grafana when using TiUP playground. Changes: - Add 'Access TiDB Dashboard and Grafana' section - Document TiDB Dashboard default credentials (root, empty password) - Document Grafana default credentials (admin/admin) - Add note about using updated root password if changed
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request introduces comprehensive documentation for the new column-level masking policy feature in TiDB. This feature is designed to enhance data security and compliance by allowing sensitive data to be masked at the column level, with masking rules configurable based on user roles and privileges. The documentation covers the feature's functionality, management, and various masking options, ensuring users can effectively implement and manage data protection. Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request introduces comprehensive documentation for TiDB's new Column-Level Masking Policy feature, including its overview, required privileges, syntax for creation and management, details on built-in masking functions (MASK_PARTIAL, MASK_FULL, MASK_NULL, MASK_DATE), conditional masking based on user/role, RESTRICT ON semantics, behavior considerations, and MySQL compatibility notes. The review comments suggest improvements to enhance the documentation's clarity, maintain an active voice, and ensure consistent markdown formatting.
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: tiancaiamao <tiancaiamao@gmail.com>
9fa5c36 to
dc69955
Compare
|
Auto-sync failed Source PR: https://github.com/pingcap/docs-cn/pull/21454/files/e83787336ac1427368e6e86196a7def3133e57d4..fc90d60de2812fd073a664777d25894218c5ed35 Translated changes were not pushed to the target branch. Please check the workflow logs for details. |
Synced from: https://github.com/pingcap/docs-cn/pull/21454/files/e83787336ac1427368e6e86196a7def3133e57d4..fc90d60de2812fd073a664777d25894218c5ed35 Target PR: #22613 AI Provider: azure Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
|
Auto-sync completed successfully Source PR: https://github.com/pingcap/docs-cn/pull/21454/files/e83787336ac1427368e6e86196a7def3133e57d4..fc90d60de2812fd073a664777d25894218c5ed35 English documentation has been updated based on Chinese documentation changes. |
Co-Authored-By: Grace Cai <qqzczy@126.com>
|
/gemini review |
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
| | `TableName` | The name of the target table. | | ||
| | `Identifier` (in parentheses) | The name of the target column. Each column can be bound to at most one masking policy. | | ||
| | `Expression` | The masking expression. You can use built-in masking functions such as `MASK_FULL`, `MASK_PARTIAL`, `MASK_NULL`, and `MASK_DATE`, or use a custom expression containing `CURRENT_USER()` or `CURRENT_ROLE()` to implement identity-based conditional masking. | | ||
| | `RESTRICT ON (...)` | Optional. Restricts specific operations on the masked column to prevent the original data from being obtained indirectly through these operations. The operations that can be restricted include `INSERT INTO SELECT`, `UPDATE SELECT`, `DELETE SELECT`, and `CTAS`. | |
There was a problem hiding this comment.
| | `RESTRICT ON (...)` | Optional. Restricts specific operations on the masked column to prevent the original data from being obtained indirectly through these operations. The operations that can be restricted include `INSERT INTO SELECT`, `UPDATE SELECT`, `DELETE SELECT`, and `CTAS`. | | |
| | `RESTRICT ON (...)` | Optional. Restricts specific operations on the masked column to prevent the original data from being obtained indirectly through these operations. The operations that can be restricted include `INSERT_INTO_SELECT`, `UPDATE_SELECT`, `DELETE_SELECT`, and `CTAS`. | |
|
|
||
| # CREATE MASKING POLICY | ||
|
|
||
| `CREATE MASKING POLICY` creates a [data masking policy](column-level-masking-policy.md) for columns in a table. After you enable a masking policy for a column, TiDB masks the results of that column according to the policy definition when returning query results, preventing sensitive data from being viewed by unauthorized users. |
There was a problem hiding this comment.
| `CREATE MASKING POLICY` creates a [data masking policy](column-level-masking-policy.md) for columns in a table. After you enable a masking policy for a column, TiDB masks the results of that column according to the policy definition when returning query results, preventing sensitive data from being viewed by unauthorized users. | |
| `CREATE MASKING POLICY` creates a [data masking policy](/column-level-masking-policy.md) for columns in a table. After you enable a masking policy for a column, TiDB masks the results of that column according to the policy definition when returning query results, preventing sensitive data from being viewed by unauthorized users. |
|
|
||
| ### Filter results using the WHERE clause | ||
|
|
||
| You can also use the `WHERE` clause to filter masking policies that meet specific conditions. For example, you can view enabled masking policies on the `employee` table as follows: |
There was a problem hiding this comment.
| You can also use the `WHERE` clause to filter masking policies that meet specific conditions. For example, you can view enabled masking policies on the `employee` table as follows: | |
| You can also use the `WHERE` clause to filter masking policies that meet specific conditions. For example, you can view enabled masking policies on the `employees` table as follows: |
|
|
||
| ### Manage column-level masking policies | ||
|
|
||
| You can use `ALTER TABLE` to manage [column-level masking policies](column-level-masking-policy.md) on tables, including adding, enabling, disabling, modifying, and dropping masking policies. |
There was a problem hiding this comment.
| You can use `ALTER TABLE` to manage [column-level masking policies](column-level-masking-policy.md) on tables, including adding, enabling, disabling, modifying, and dropping masking policies. | |
| You can use `ALTER TABLE` to manage [column-level masking policies](/column-level-masking-policy.md) on tables, including adding, enabling, disabling, modifying, and dropping masking policies. |
|
|
||
| # SHOW MASKING POLICIES | ||
|
|
||
| The `SHOW MASKING POLICIES` statement lets you view information about the [Column-level masking policies](column-level-masking-policy.md) defined on a specified table. |
There was a problem hiding this comment.
| The `SHOW MASKING POLICIES` statement lets you view information about the [Column-level masking policies](column-level-masking-policy.md) defined on a specified table. | |
| The `SHOW MASKING POLICIES` statement lets you view information about the [Column-level masking policies](/column-level-masking-policy.md) defined on a specified table. |
|
@bb7133: adding LGTM is restricted to approvers and reviewers in OWNERS files. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
hold this PR because the related code is not fully ready according to @tiancaiamao |
First-time contributors' checklist
What is changed, added or deleted? (Required)
Which TiDB version(s) do your changes apply to? (Required)
Tips for choosing the affected version(s):
By default, CHOOSE MASTER ONLY so your changes will be applied to the next TiDB major or minor releases. If your PR involves a product feature behavior change or a compatibility change, CHOOSE THE AFFECTED RELEASE BRANCH(ES) AND MASTER.
For details, see tips for choosing the affected versions.
What is the related PR or file link(s)?
Do your changes match any of the following descriptions?