IAM: Add ExternalGroupMapping kind for TeamSync (#113052)

* wip

* wip

* Add authorizer -> VERIFY it's working correctly

* Update openapi definitions

* Authorizer wip

* regen apis

* Increase timeout of pg int tests to 20m

* Revert "Increase timeout of pg int tests to 20m"

This reverts commit 8c20568217.

* Fix NewTestStore when Truncate is enabled
This commit is contained in:
Misi
2025-11-05 18:02:34 +01:00
committed by GitHub
parent daa28773d6
commit 06373ae47b
22 changed files with 2179 additions and 48 deletions
+3 -1
View File
@@ -7,6 +7,7 @@ import (
"strings"
"github.com/grafana/authlib/types"
"github.com/grafana/grafana/pkg/registry/apis/iam/common"
"github.com/grafana/grafana/pkg/registry/apis/iam/legacy"
"github.com/grafana/grafana/pkg/services/accesscontrol"
)
@@ -54,7 +55,7 @@ func (s *Service) newServiceAccountNameResolver(ctx context.Context, ns types.Na
func (s *Service) fetchTeams(ctx context.Context, ns types.NamespaceInfo) (map[int64]string, error) {
key := teamIDsCacheKey(ns.Value)
res, err, _ := s.sf.Do(key, func() (any, error) {
teams, err := s.identityStore.ListTeams(ctx, ns, legacy.ListTeamQuery{})
teams, err := s.identityStore.ListTeams(ctx, ns, legacy.ListTeamQuery{Pagination: common.Pagination{Limit: 100}})
if err != nil {
return nil, fmt.Errorf("could not fetch teams: %w", err)
}
@@ -170,6 +171,7 @@ func (s *Service) nameResolver(ctx context.Context, ns types.NamespaceInfo, scop
if scopePrefix == "teams:id:" {
return s.newTeamNameResolver(ctx, ns)
}
if scopePrefix == "permissions:type:" {
return permissionsDelegateResolverFunc, nil
}