Access Control: Add fine-grained access control to ldap handlers (#35525)
* Add new accesscontrol action for ldap config reload * Update ldapAdminEditRole with new ldap config reload permission * wrap /ldap/reload with accesscontrol authorize middleware * document new action and update fixed:ldap:admin:edit with said action * add fake accesscontrol implementation for tests * Add accesscontrol tests for ldap handlers Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com>
This commit is contained in:
co-authored by
Ursula Kallio
parent
6707b61434
commit
36c997a625
@@ -75,9 +75,10 @@ const (
|
||||
ActionOrgUsersRoleUpdate = "org.users.role:update"
|
||||
|
||||
// LDAP actions
|
||||
ActionLDAPUsersRead = "ldap.user:read"
|
||||
ActionLDAPUsersSync = "ldap.user:sync"
|
||||
ActionLDAPStatusRead = "ldap.status:read"
|
||||
ActionLDAPUsersRead = "ldap.user:read"
|
||||
ActionLDAPUsersSync = "ldap.user:sync"
|
||||
ActionLDAPStatusRead = "ldap.status:read"
|
||||
ActionLDAPConfigReload = "ldap.config:reload"
|
||||
|
||||
// Global Scopes
|
||||
ScopeGlobalUsersAll = "global:users:*"
|
||||
|
||||
@@ -17,11 +17,14 @@ var ldapAdminReadRole = RoleDTO{
|
||||
|
||||
var ldapAdminEditRole = RoleDTO{
|
||||
Name: ldapAdminEdit,
|
||||
Version: 1,
|
||||
Version: 2,
|
||||
Permissions: ConcatPermissions(ldapAdminReadRole.Permissions, []Permission{
|
||||
{
|
||||
Action: ActionLDAPUsersSync,
|
||||
},
|
||||
{
|
||||
Action: ActionLDAPConfigReload,
|
||||
},
|
||||
}),
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user