diff --git a/apps/provisioning/pkg/auth/round_tripper.go b/apps/provisioning/pkg/auth/round_tripper.go index 535dda9bb88..f5da0d778f0 100644 --- a/apps/provisioning/pkg/auth/round_tripper.go +++ b/apps/provisioning/pkg/auth/round_tripper.go @@ -66,8 +66,6 @@ func NewRoundTripper(tokenExchangeClient tokenExchanger, base http.RoundTripper, // RoundTrip exchanges credentials for an access token and injects it into the request. // The token is scoped to all configured audiences and the wildcard namespace ("*"). -// If a user identity is present in the request context, its ID token is forwarded -// in the X-Grafana-Id header so aggregators can forward it to MT API servers. func (t *RoundTripper) RoundTrip(req *http.Request) (*http.Response, error) { audiences := []string{t.audience} if t.extraAudience != "" && t.extraAudience != t.audience { @@ -84,13 +82,5 @@ func (t *RoundTripper) RoundTrip(req *http.Request) (*http.Response, error) { req = utilnet.CloneRequest(req) req.Header.Set("X-Access-Token", "Bearer "+tokenResponse.Token) - - // Forward user ID token from context if present, so aggregators can forward it to MT - if requester, err := identity.GetRequester(req.Context()); err == nil && requester != nil { - if idToken := requester.GetIDToken(); idToken != "" { - req.Header.Set("X-Grafana-Id", idToken) - } - } - return t.transport.RoundTrip(req) } diff --git a/pkg/registry/apis/provisioning/register.go b/pkg/registry/apis/provisioning/register.go index fa895b3e733..e116dfcd8cf 100644 --- a/pkg/registry/apis/provisioning/register.go +++ b/pkg/registry/apis/provisioning/register.go @@ -520,10 +520,6 @@ func authorizeRoleBasedResource(ctx context.Context, resource string, id identit if authInfo, ok := authlib.AuthInfoFrom(ctx); ok { isAccessPolicy = authlib.IsIdentityType(authInfo.GetIdentityType(), authlib.TypeAccessPolicy) } - // Also check AuthID for AccessPolicy identities (Extended JWT may set TypeUser but AuthID is "access-policy:...") - if !isAccessPolicy && id.GetAuthID() != "" { - isAccessPolicy = strings.HasPrefix(id.GetAuthID(), "access-policy:") - } } switch resource {