AuthN: Extract enable disabled users logic to its own hook (#63628)
This commit is contained in:
@@ -159,6 +159,23 @@ func (s *UserSync) SyncLastSeenHook(ctx context.Context, identity *authn.Identit
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *UserSync) EnableDisabledUserHook(ctx context.Context, identity *authn.Identity, _ *authn.Request) error {
|
||||
if !identity.ClientParams.EnableDisabledUsers {
|
||||
return nil
|
||||
}
|
||||
|
||||
if !identity.IsDisabled {
|
||||
return nil
|
||||
}
|
||||
|
||||
namespace, id := identity.NamespacedID()
|
||||
if namespace != authn.NamespaceUser {
|
||||
return nil
|
||||
}
|
||||
|
||||
return s.userService.Disable(ctx, &user.DisableUserCommand{UserID: id, IsDisabled: false})
|
||||
}
|
||||
|
||||
func (s *UserSync) upsertAuthConnection(ctx context.Context, userID int64, identity *authn.Identity, createConnection bool) error {
|
||||
if identity.AuthModule == "" {
|
||||
return nil
|
||||
@@ -217,17 +234,6 @@ func (s *UserSync) updateUserAttributes(ctx context.Context, usr *user.User, id
|
||||
}
|
||||
}
|
||||
|
||||
// FIXME(kalleep): Should this be its own hook?
|
||||
if usr.IsDisabled && id.ClientParams.EnableDisabledUsers {
|
||||
usr.IsDisabled = false
|
||||
if errDisableUser := s.userService.Disable(
|
||||
ctx,
|
||||
&user.DisableUserCommand{UserID: usr.ID, IsDisabled: false},
|
||||
); errDisableUser != nil {
|
||||
return errDisableUser
|
||||
}
|
||||
}
|
||||
|
||||
// Sync isGrafanaAdmin permission
|
||||
if id.IsGrafanaAdmin != nil && *id.IsGrafanaAdmin != usr.IsAdmin {
|
||||
usr.IsAdmin = *id.IsGrafanaAdmin
|
||||
|
||||
Reference in New Issue
Block a user