RBAC: Feature to override default assignments (#66561)

* RBAC: Feature to override default assignments

Co-authored-by: Kalle Persson <kalle.persson@grafana.com>

* Add test and trim spaces

* Pass linting

* Apply the rbac overrides to fixed_authentication.config_writer

* Removing from the default ini file for now

* Add grants overrides section to cfg

* slimmer handleGrantOverrides function

---------

Co-authored-by: Kalle Persson <kalle.persson@grafana.com>
This commit is contained in:
Gabriel MABILLE
2023-04-14 17:17:59 +02:00
committed by GitHub
co-authored by Kalle Persson
parent 02951e8a26
commit 3b63844390
5 changed files with 106 additions and 5 deletions
+14
View File
@@ -505,6 +505,9 @@ type Cfg struct {
RBACPermissionValidationEnabled bool
// Reset basic roles permissions on start-up
RBACResetBasicRoles bool
// Override default fixed role assignments
RBACGrantOverrides map[string][]string
// GRPC Server.
GRPCServerNetwork string
GRPCServerAddress string
@@ -1559,6 +1562,17 @@ func readAccessControlSettings(iniFile *ini.File, cfg *Cfg) {
cfg.RBACPermissionCache = rbac.Key("permission_cache").MustBool(true)
cfg.RBACPermissionValidationEnabled = rbac.Key("permission_validation_enabled").MustBool(false)
cfg.RBACResetBasicRoles = rbac.Key("reset_basic_roles").MustBool(false)
rbacOverrides := iniFile.Section("rbac.overrides")
cfg.RBACGrantOverrides = map[string][]string{}
for _, key := range rbacOverrides.Keys() {
value := key.MustString("")
grants := strings.Split(value, ",")
for i, grant := range grants {
grants[i] = strings.TrimSpace(grant)
}
cfg.RBACGrantOverrides[key.Name()] = grants
}
}
func readUserSettings(iniFile *ini.File, cfg *Cfg) error {