AuthZ: Further protect admin endpoints (#86285)

* only users with Grafana Admin role can grant/revoke Grafana Admin role

* check permissions to user amdin endpoints globally

* allow checking global permissions for service accounts

* use a middleware for checking whether the caller is Grafana Admin
This commit is contained in:
Ieva
2024-04-16 15:48:12 +01:00
committed by GitHub
parent 0f06120b56
commit 036f826b87
2 changed files with 12 additions and 11 deletions
+1
View File
@@ -353,6 +353,7 @@ func (s *Service) resolveIdenity(ctx context.Context, orgID int64, namespaceID a
ID: namespaceID.String(),
OrgID: orgID,
ClientParams: authn.ClientParams{
AllowGlobalOrg: true,
FetchSyncedUser: true,
SyncPermissions: true,
}}, nil