Access Control: Add fine-grained access control to explore (#35883)
* add fixed role for datasource read operations * Add action for datasource explore * add authorize middleware to explore index route * add fgac support for explore navlink * update hasAccessToExplore to check if accesscontrol is enable and evalute action if it is * add getExploreRoles to evalute roles based onaccesscontrol, viewersCanEdit and default * create function to evaluate permissions or using fallback if accesscontrol is disabled * change hasAccess to prop and derive the value in mapStateToProps * add test case to ensure buttons is not rendered when user does not have access * Only hide return with changes button * remove internal links if user does not have access to explorer Co-authored-by: Ivana Huckova <30407135+ivanahuckova@users.noreply.github.com>
This commit is contained in:
co-authored by
Ivana Huckova
parent
ef05596e07
commit
2fd7031102
@@ -42,7 +42,6 @@ func (p RoleDTO) Role() Role {
|
||||
const (
|
||||
// Permission actions
|
||||
|
||||
// Actions
|
||||
// Provisioning actions
|
||||
ActionProvisioningReload = "provisioning:reload"
|
||||
|
||||
@@ -86,6 +85,9 @@ const (
|
||||
// Settings actions
|
||||
ActionSettingsRead = "settings:read"
|
||||
|
||||
// Datasources actions
|
||||
ActionDatasourcesExplore = "datasources:explore"
|
||||
|
||||
// Global Scopes
|
||||
ScopeGlobalUsersAll = "global:users:*"
|
||||
|
||||
|
||||
@@ -2,6 +2,16 @@ package accesscontrol
|
||||
|
||||
import "github.com/grafana/grafana/pkg/models"
|
||||
|
||||
var datasourcesEditorReadRole = RoleDTO{
|
||||
Version: 1,
|
||||
Name: datasourcesEditorRead,
|
||||
Permissions: []Permission{
|
||||
{
|
||||
Action: ActionDatasourcesExplore,
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
var ldapAdminReadRole = RoleDTO{
|
||||
Name: ldapAdminRead,
|
||||
Version: 1,
|
||||
@@ -166,7 +176,8 @@ var provisioningAdminRole = RoleDTO{
|
||||
// resource. FixedRoleGrants lists which built-in roles are
|
||||
// assigned which fixed roles in this list.
|
||||
var FixedRoles = map[string]RoleDTO{
|
||||
serverAdminRead: serverAdminReadRole,
|
||||
datasourcesEditorRead: datasourcesEditorReadRole,
|
||||
serverAdminRead: serverAdminReadRole,
|
||||
|
||||
settingsAdminRead: settingsAdminReadRole,
|
||||
|
||||
@@ -183,6 +194,8 @@ var FixedRoles = map[string]RoleDTO{
|
||||
}
|
||||
|
||||
const (
|
||||
datasourcesEditorRead = "fixed:datasources:editor:read"
|
||||
|
||||
serverAdminRead = "fixed:server:admin:read"
|
||||
|
||||
settingsAdminRead = "fixed:settings:admin:read"
|
||||
@@ -217,6 +230,9 @@ var FixedRoleGrants = map[string][]string{
|
||||
usersOrgEdit,
|
||||
usersOrgRead,
|
||||
},
|
||||
string(models.ROLE_EDITOR): {
|
||||
datasourcesEditorRead,
|
||||
},
|
||||
}
|
||||
|
||||
func ConcatPermissions(permissions ...[]Permission) []Permission {
|
||||
|
||||
Reference in New Issue
Block a user