RBAC: Allow listing user permissions with scope (#57538)

* RBAC: Allow listing user permissions with scope

* Add docs

* Document the api endpoint

* Update docs

Co-authored-by: Garrett Guillotte <100453168+gguillotte-grafana@users.noreply.github.com>

* Split endpoint in two

* document reloadcache

* Update docs/sources/developers/http_api/access_control.md

* Fix test

* Ieva's nit.

* Simplify flag description

Co-authored-by: Garrett Guillotte <100453168+gguillotte-grafana@users.noreply.github.com>
This commit is contained in:
Gabriel MABILLE
2022-11-02 10:48:11 +01:00
committed by GitHub
co-authored by Garrett Guillotte
parent f1f0a6f88b
commit 101ce57a94
5 changed files with 247 additions and 6 deletions
@@ -527,11 +527,60 @@ Content-Type: application/json; charset=UTF-8
| 403 | Access denied. |
| 500 | Unexpected error. Refer to body and/or server logs for more details. |
### List your permissions
`GET /api/access-control/users/permissions`
Lists the permissions granted to the signed in user.
#### Required permissions
No permission is required.
#### Query parameters
| Param | Type | Required | Description |
| ----------- | ------- | -------- | -------------------------------------- |
| reloadcache | boolean | No | A flag to reload the permission cache. |
#### Example request
```http
GET /api/access-control/user/permissions
Accept: application/json
```
#### Example response
```http
HTTP/1.1 200 OK
Content-Type: application/json; charset=UTF-8
{
"dashboards:read": ["dashboards:uid:70KrY6IVz"],
"dashboards:write": ["dashboards:uid:70KrY6IVz"],
"datasources.id:read": ["datasources:*"],
"datasources:read": ["datasources:*"],
"datasources:explore": [""],
"datasources:query": ["datasources:uid:grafana"],
"datasources:read": ["datasources:uid:grafana"],
"orgs:read": [""]
}
```
#### Status codes
| Code | Description |
| ---- | -------------------------------------------------------------------- |
| 200 | Set of assigned permissions is returned. |
| 403 | Access denied. |
| 500 | Unexpected error. Refer to body and/or server logs for more details. |
### List permissions assigned to a user
`GET /api/access-control/users/:userId/permissions`
Lists the permissions that a given user has.
Lists the permissions granted to a given user.
#### Required permissions