Access Control: Add fine-grained access control to explore (#35883)

* add fixed role for datasource read operations

* Add action for datasource explore

* add authorize middleware to explore index route

* add fgac support for explore navlink

* update hasAccessToExplore to check if accesscontrol is enable and evalute action if it is

* add getExploreRoles to evalute roles based onaccesscontrol, viewersCanEdit and default

* create function to evaluate permissions or using fallback if accesscontrol is disabled

* change hasAccess to prop and derive the value in mapStateToProps

* add test case to ensure buttons is not rendered when user does not have access

* Only hide return with changes button

* remove internal links if user does not have access to explorer

Co-authored-by: Ivana Huckova <30407135+ivanahuckova@users.noreply.github.com>
This commit is contained in:
Karl Persson
2021-07-02 14:43:12 +02:00
committed by GitHub
co-authored by Ivana Huckova
parent ef05596e07
commit 2fd7031102
13 changed files with 150 additions and 34 deletions
+3 -1
View File
@@ -42,7 +42,6 @@ func (p RoleDTO) Role() Role {
const (
// Permission actions
// Actions
// Provisioning actions
ActionProvisioningReload = "provisioning:reload"
@@ -86,6 +85,9 @@ const (
// Settings actions
ActionSettingsRead = "settings:read"
// Datasources actions
ActionDatasourcesExplore = "datasources:explore"
// Global Scopes
ScopeGlobalUsersAll = "global:users:*"
+17 -1
View File
@@ -2,6 +2,16 @@ package accesscontrol
import "github.com/grafana/grafana/pkg/models"
var datasourcesEditorReadRole = RoleDTO{
Version: 1,
Name: datasourcesEditorRead,
Permissions: []Permission{
{
Action: ActionDatasourcesExplore,
},
},
}
var ldapAdminReadRole = RoleDTO{
Name: ldapAdminRead,
Version: 1,
@@ -166,7 +176,8 @@ var provisioningAdminRole = RoleDTO{
// resource. FixedRoleGrants lists which built-in roles are
// assigned which fixed roles in this list.
var FixedRoles = map[string]RoleDTO{
serverAdminRead: serverAdminReadRole,
datasourcesEditorRead: datasourcesEditorReadRole,
serverAdminRead: serverAdminReadRole,
settingsAdminRead: settingsAdminReadRole,
@@ -183,6 +194,8 @@ var FixedRoles = map[string]RoleDTO{
}
const (
datasourcesEditorRead = "fixed:datasources:editor:read"
serverAdminRead = "fixed:server:admin:read"
settingsAdminRead = "fixed:settings:admin:read"
@@ -217,6 +230,9 @@ var FixedRoleGrants = map[string][]string{
usersOrgEdit,
usersOrgRead,
},
string(models.ROLE_EDITOR): {
datasourcesEditorRead,
},
}
func ConcatPermissions(permissions ...[]Permission) []Permission {