Alerting: update authorization logic to use proper legacy roles when fine-grained access is disabled (#46931)
* require legacy Editor for post, put, delete endpoints * require user to be signed in on group level because handler that checks that user has role Editor does not check it is signed in
This commit is contained in:
@@ -26,6 +26,17 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
authorize := acmiddleware.Middleware(api.AccessControl)
|
||||
var eval ac.Evaluator = nil
|
||||
|
||||
// Most routes follow this general authorization approach as a fallback. Exceptions are overridden directly in the below block.
|
||||
var fallback web.Handler
|
||||
switch method {
|
||||
case http.MethodPost, http.MethodPut, http.MethodDelete:
|
||||
fallback = middleware.ReqEditorRole
|
||||
case http.MethodGet:
|
||||
fallback = middleware.ReqSignedIn
|
||||
default:
|
||||
fallback = middleware.ReqSignedIn
|
||||
}
|
||||
|
||||
switch method + path {
|
||||
// Alert Rules
|
||||
|
||||
@@ -55,9 +66,11 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
|
||||
// Grafana Rules Testing Paths
|
||||
case http.MethodPost + "/api/v1/rule/test/grafana":
|
||||
fallback = middleware.ReqSignedIn
|
||||
// additional authorization is done in the request handler
|
||||
eval = ac.EvalPermission(ac.ActionAlertingRuleRead)
|
||||
case http.MethodPost + "/api/v1/eval":
|
||||
fallback = middleware.ReqSignedIn
|
||||
// additional authorization is done in the request handler
|
||||
eval = ac.EvalPermission(ac.ActionAlertingRuleRead)
|
||||
|
||||
@@ -81,6 +94,7 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
|
||||
// Lotex Rules testing
|
||||
case http.MethodPost + "/api/v1/rule/test/{Recipient}":
|
||||
fallback = middleware.ReqSignedIn
|
||||
eval = ac.EvalPermission(ac.ActionAlertingRuleExternalRead, datasources.ScopeProvider.GetResourceScope(ac.Parameter(":Recipient")))
|
||||
|
||||
// Alert Instances and Silences
|
||||
@@ -136,6 +150,7 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
case http.MethodDelete + "/api/alertmanager/grafana/config/api/v1/alerts": // reset alertmanager config to the default
|
||||
eval = ac.EvalPermission(ac.ActionAlertingNotificationsDelete)
|
||||
case http.MethodGet + "/api/alertmanager/grafana/config/api/v1/alerts":
|
||||
fallback = middleware.ReqEditorRole
|
||||
eval = ac.EvalPermission(ac.ActionAlertingNotificationsRead)
|
||||
case http.MethodGet + "/api/alertmanager/grafana/api/v2/status":
|
||||
eval = ac.EvalPermission(ac.ActionAlertingNotificationsRead)
|
||||
@@ -143,6 +158,7 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
// additional authorization is done in the request handler
|
||||
eval = ac.EvalAny(ac.EvalPermission(ac.ActionAlertingNotificationsUpdate), ac.EvalPermission(ac.ActionAlertingNotificationsCreate), ac.EvalPermission(ac.ActionAlertingNotificationsDelete))
|
||||
case http.MethodPost + "/api/alertmanager/grafana/config/api/v1/receivers/test":
|
||||
fallback = middleware.ReqEditorRole
|
||||
eval = ac.EvalPermission(ac.ActionAlertingNotificationsRead)
|
||||
|
||||
// External Alertmanager Paths
|
||||
@@ -166,7 +182,7 @@ func (api *API) authorize(method, path string) web.Handler {
|
||||
}
|
||||
|
||||
if eval != nil {
|
||||
return authorize(middleware.ReqSignedIn, eval)
|
||||
return authorize(fallback, eval)
|
||||
}
|
||||
|
||||
panic(fmt.Sprintf("no authorization handler for method [%s] of endpoint [%s]", method, path))
|
||||
|
||||
Reference in New Issue
Block a user