Zanzana: List then search implementation (#96705)
* Zanzana: Search with list * Allow to pass werb into list request * split list search into 2 functions * fix listing resources * remove unused * refactor * remove unused function * Add more logging to reconciler * Fix search for users with access to all resources * fix findFoldersZanzanaList * search for folders as well by default * refactor * use compile for list and search * remove list from client * remove only from client * remove list from interface * run compile once * refactor * refactor * add search tests * fix tests * Fix linter
This commit is contained in:
@@ -4,7 +4,6 @@ import (
|
||||
"context"
|
||||
|
||||
"github.com/grafana/authlib/authz"
|
||||
"github.com/grafana/authlib/claims"
|
||||
|
||||
authzextv1 "github.com/grafana/grafana/pkg/services/authz/proto/v1"
|
||||
"github.com/grafana/grafana/pkg/services/authz/zanzana/client"
|
||||
@@ -13,7 +12,6 @@ import (
|
||||
// Client is a wrapper around [openfgav1.OpenFGAServiceClient]
|
||||
type Client interface {
|
||||
authz.AccessClient
|
||||
List(ctx context.Context, id claims.AuthInfo, req authz.ListRequest) (*authzextv1.ListResponse, error)
|
||||
Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error)
|
||||
Write(ctx context.Context, req *authzextv1.WriteRequest) error
|
||||
BatchCheck(ctx context.Context, req *authzextv1.BatchCheckRequest) (*authzextv1.BatchCheckResponse, error)
|
||||
|
||||
@@ -142,19 +142,6 @@ func newItemChecker(res *authzextv1.ListResponse) authz.ItemChecker {
|
||||
}
|
||||
}
|
||||
|
||||
func (c *Client) List(ctx context.Context, id claims.AuthInfo, req authz.ListRequest) (*authzextv1.ListResponse, error) {
|
||||
ctx, span := tracer.Start(ctx, "authz.zanzana.client.List")
|
||||
defer span.End()
|
||||
|
||||
return c.authzext.List(ctx, &authzextv1.ListRequest{
|
||||
Subject: id.GetUID(),
|
||||
Group: req.Group,
|
||||
Verb: utils.VerbList,
|
||||
Resource: req.Resource,
|
||||
Namespace: req.Namespace,
|
||||
})
|
||||
}
|
||||
|
||||
func (c *Client) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
|
||||
ctx, span := tracer.Start(ctx, "authz.zanzana.client.Read")
|
||||
defer span.End()
|
||||
|
||||
@@ -25,10 +25,6 @@ func (nc *NoopClient) Compile(ctx context.Context, id claims.AuthInfo, req authz
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (nc *NoopClient) List(ctx context.Context, id claims.AuthInfo, req authz.ListRequest) (*authzextv1.ListResponse, error) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (nc NoopClient) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
@@ -4,9 +4,8 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
openfgav1 "github.com/openfga/api/proto/openfga/v1"
|
||||
|
||||
"github.com/grafana/authlib/authz"
|
||||
openfgav1 "github.com/openfga/api/proto/openfga/v1"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/authz/zanzana/common"
|
||||
)
|
||||
@@ -154,6 +153,23 @@ func TranslateToCheckRequest(namespace, action, kind, folder, name string) (*aut
|
||||
return req, true
|
||||
}
|
||||
|
||||
func TranslateToListRequest(namespace, action, kind string) (*authz.ListRequest, bool) {
|
||||
translation, ok := resourceTranslations[kind]
|
||||
|
||||
if !ok {
|
||||
return nil, false
|
||||
}
|
||||
|
||||
// FIXME: support different verbs
|
||||
req := &authz.ListRequest{
|
||||
Namespace: namespace,
|
||||
Group: translation.group,
|
||||
Resource: translation.resource,
|
||||
}
|
||||
|
||||
return req, true
|
||||
}
|
||||
|
||||
func TranslateToGroupResource(kind string) string {
|
||||
translation, ok := resourceTranslations[kind]
|
||||
if !ok {
|
||||
|
||||
Reference in New Issue
Block a user