DESCRIBE MASKING POLICY¶
描述有关掩码策略的详细信息,包括创建日期、名称、数据类型和 SQL 表达式。
DESCRIBE 可以缩写为 DESC。
- 另请参阅:
语法¶
DESC[RIBE] MASKING POLICY <name>
参数¶
- name
- 掩码策略的标识符;对于您的账户必须是唯一的。 - 标识符值必须以字母字符开头,且不能包含空格或特殊字符,除非整个标识符字符串放在双引号内(例如 - "My object")。放在双引号内的标识符也区分大小写。- 有关更多详细信息,请参阅 标识符要求。 
访问控制要求¶
用于执行此 SQL 命令的 角色 必须至少具有以下 一项 权限:
| 权限 | 对象 | 备注 | 
|---|---|---|
| APPLY MASKING POLICY | 账户 | |
| APPLY | 掩码策略 | |
| OWNERSHIP | 掩码策略 | OWNERSHIP is a special privilege on an object that is automatically granted to the role that created the object, but can also be transferred using the GRANT OWNERSHIP command to a different role by the owning role (or any role with the MANAGE GRANTS privilege). | 
The USAGE privilege on the parent database and schema are required to perform operations on any object in a schema. Note that a role granted any privilege on a schema allows that role to resolve the schema. For example, a role granted CREATE privilege on a schema can create objects on that schema without also having USAGE granted on that schema.
有关创建具有指定权限集的自定义角色的说明,请参阅 创建自定义角色。
有关对 安全对象 执行 SQL 操作的相应角色和权限授予的一般信息,请参阅 访问控制概述。
有关掩码策略 DDL 和权限的其他详细信息,请参阅 管理列级安全性。
使用说明¶
- To post-process the output of this command, you can use the pipe operator ( - ->>) or the RESULT_SCAN function. Both constructs treat the output as a result set that you can query.- The output column names for this command are generated in lowercase. If you consume a result set from this command with the pipe operator or the RESULT_SCAN function, use double-quoted identifiers for the column names in the query to ensure that they match the column names in the output that was scanned. For example, if the name of an output column is - type, then specify- "type"for the identifier.
示例¶
DESC MASKING POLICY ssn_mask;
+-----+------------+---------------+-------------------+-----------------------------------------------------------------------+
| Row | name       | signature     | return_type       | body                                                                  |
+-----+------------+---------------+-------------------+-----------------------------------------------------------------------+
| 1   | SSN_MASK   | (VAL VARCHAR) | VARCHAR(16777216) | case when current_role() in ('ANALYST') then val else '*********' end |
+-----+------------+---------------+-------------------+-----------------------------------------------------------------------+