Provisioning: Fix check of who can update (#110835)
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"slices"
|
||||
|
||||
apierrors "k8s.io/apimachinery/pkg/api/errors"
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
@@ -17,6 +18,7 @@ import (
|
||||
|
||||
authtypes "github.com/grafana/authlib/types"
|
||||
|
||||
provisioning "github.com/grafana/grafana/apps/provisioning/pkg/apis/provisioning/v0alpha1"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
"github.com/grafana/grafana/pkg/storage/unified/resourcepb"
|
||||
)
|
||||
@@ -75,7 +77,7 @@ func enforceManagerProperties(auth authtypes.AuthInfo, obj utils.GrafanaMetaAcce
|
||||
return nil // not managed
|
||||
|
||||
case utils.ManagerKindRepo:
|
||||
if auth.GetUID() == "access-policy:provisioning" {
|
||||
if auth.GetUID() == "access-policy:provisioning" || slices.Contains(auth.GetAudience(), provisioning.GROUP) {
|
||||
return nil // OK!
|
||||
}
|
||||
// This can fallback to writing the value with a provisioning client
|
||||
|
||||
@@ -4,15 +4,19 @@ import (
|
||||
"context"
|
||||
"testing"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/stretchr/testify/require"
|
||||
v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
|
||||
authnlib "github.com/grafana/authlib/authn"
|
||||
authtypes "github.com/grafana/authlib/types"
|
||||
dashboard "github.com/grafana/grafana/apps/dashboard/pkg/apis/dashboard/v1beta1"
|
||||
provisioning "github.com/grafana/grafana/apps/provisioning/pkg/apis/provisioning/v0alpha1"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
serviceauthn "github.com/grafana/grafana/pkg/services/authn"
|
||||
)
|
||||
|
||||
func TestManagedAuthorizer(t *testing.T) {
|
||||
@@ -112,6 +116,25 @@ func TestManagedAuthorizer(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "audience includes provisioning group",
|
||||
auth: &serviceauthn.Identity{
|
||||
Type: authtypes.TypeAccessPolicy,
|
||||
UID: "access-policy:random-uid",
|
||||
AccessTokenClaims: &authnlib.Claims[authnlib.AccessTokenClaims]{
|
||||
Claims: jwt.Claims{
|
||||
Audience: []string{provisioning.GROUP},
|
||||
},
|
||||
},
|
||||
},
|
||||
obj: &dashboard.Dashboard{
|
||||
ObjectMeta: v1.ObjectMeta{
|
||||
Annotations: map[string]string{
|
||||
utils.AnnoKeyManagerKind: string(utils.ManagerKindRepo),
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
Reference in New Issue
Block a user