Revert "Fix AccessPolicy identity detection in ST authorizer"

This reverts commit 0f4885e503.
This commit is contained in:
Roberto Jimenez Sanchez
2025-12-18 10:52:49 +01:00
parent 0f4885e503
commit 1e5adf7529
2 changed files with 0 additions and 14 deletions
@@ -66,8 +66,6 @@ func NewRoundTripper(tokenExchangeClient tokenExchanger, base http.RoundTripper,
// RoundTrip exchanges credentials for an access token and injects it into the request.
// The token is scoped to all configured audiences and the wildcard namespace ("*").
// If a user identity is present in the request context, its ID token is forwarded
// in the X-Grafana-Id header so aggregators can forward it to MT API servers.
func (t *RoundTripper) RoundTrip(req *http.Request) (*http.Response, error) {
audiences := []string{t.audience}
if t.extraAudience != "" && t.extraAudience != t.audience {
@@ -84,13 +82,5 @@ func (t *RoundTripper) RoundTrip(req *http.Request) (*http.Response, error) {
req = utilnet.CloneRequest(req)
req.Header.Set("X-Access-Token", "Bearer "+tokenResponse.Token)
// Forward user ID token from context if present, so aggregators can forward it to MT
if requester, err := identity.GetRequester(req.Context()); err == nil && requester != nil {
if idToken := requester.GetIDToken(); idToken != "" {
req.Header.Set("X-Grafana-Id", idToken)
}
}
return t.transport.RoundTrip(req)
}
@@ -520,10 +520,6 @@ func authorizeRoleBasedResource(ctx context.Context, resource string, id identit
if authInfo, ok := authlib.AuthInfoFrom(ctx); ok {
isAccessPolicy = authlib.IsIdentityType(authInfo.GetIdentityType(), authlib.TypeAccessPolicy)
}
// Also check AuthID for AccessPolicy identities (Extended JWT may set TypeUser but AuthID is "access-policy:...")
if !isAccessPolicy && id.GetAuthID() != "" {
isAccessPolicy = strings.HasPrefix(id.GetAuthID(), "access-policy:")
}
}
switch resource {