RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)
* Unexport store and create new constructor function * Add ResourceAuthorizer and LegacyAccessClient * Configure checks for user store * List with checks if AccessClient is configured * Allow system user service account to read all users --------- Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
co-authored by
Gabriel MABILLE
parent
bca8bd3c8b
commit
2e38329026
@@ -0,0 +1,7 @@
|
||||
SELECT u.id
|
||||
FROM {{ .Ident .UserTable }} as u
|
||||
INNER JOIN {{ .Ident .OrgUserTable }} as o ON u.id = o.user_id
|
||||
WHERE o.org_id = {{ .Arg .Query.OrgID }}
|
||||
AND u.uid = {{ .Arg .Query.UID }}
|
||||
AND NOT u.is_service_account
|
||||
LIMIT 1;
|
||||
Reference in New Issue
Block a user