AuthZ: Further protect admin endpoints (#86285)
* only users with Grafana Admin role can grant/revoke Grafana Admin role * check permissions to user amdin endpoints globally * allow checking global permissions for service accounts * use a middleware for checking whether the caller is Grafana Admin
This commit is contained in:
@@ -353,6 +353,7 @@ func (s *Service) resolveIdenity(ctx context.Context, orgID int64, namespaceID a
|
||||
ID: namespaceID.String(),
|
||||
OrgID: orgID,
|
||||
ClientParams: authn.ClientParams{
|
||||
AllowGlobalOrg: true,
|
||||
FetchSyncedUser: true,
|
||||
SyncPermissions: true,
|
||||
}}, nil
|
||||
|
||||
Reference in New Issue
Block a user