Access control: FGAC for team sync endpoints (#44673) (#44856)

* add actions for team group sync

* extend the hook to allow specifying whether the user is external

* move user struct to type package

* interface for permission service to allow mocking it

* reuse existing permissions

* test fix

* refactor

* linting

(cherry picked from commit 602d62ebcc)

Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
Grot (@grafanabot)
2022-02-03 15:48:13 +00:00
committed by GitHub
co-authored by Ieva
parent 9e0acc9ece
commit 358db0d130
14 changed files with 76 additions and 28 deletions
@@ -160,7 +160,7 @@ func TestApi_getPermissions(t *testing.T) {
// seed user 1 with "View" permission on dashboard 1
u, err := sql.CreateUser(context.Background(), models.CreateUserCommand{Login: "test", OrgId: 1})
require.NoError(t, err)
_, err = service.SetUserPermission(context.Background(), u.OrgId, u.Id, tt.resourceID, "View")
_, err = service.SetUserPermission(context.Background(), u.OrgId, accesscontrol.User{ID: u.Id}, tt.resourceID, "View")
require.NoError(t, err)
// seed built in role Admin with "Edit" permission on dashboard 1