Alerting: fix bug where user is able to access rules from namespaces user is not part of (#41403) (#41406)
* Add fix
* Add tests
(cherry picked from commit 6220872633)
Co-authored-by: Yuriy Tseretyan <yuriy.tseretyan@grafana.com>
Co-authored-by: Armand Grillet <2117580+armandgrillet@users.noreply.github.com>
Co-authored-by: Jean-Philippe Quéméner <JohnnyQQQQ@users.noreply.github.com>
Co-authored-by: George Robinson <george.robinson@grafana.com>
Co-authored-by: gotjosh <josue@grafana.com>
This commit is contained in:
co-authored by
Yuriy Tseretyan
Armand Grillet
Jean-Philippe Quéméner
George Robinson
gotjosh
parent
adfd39e5fd
commit
3b8be57b4f
@@ -152,6 +152,12 @@ func (srv RulerSrv) RouteGetRulesConfig(c *models.ReqContext) response.Response
|
||||
if err != nil {
|
||||
return ErrResp(http.StatusInternalServerError, err, "failed to get namespaces visible to the user")
|
||||
}
|
||||
result := apimodels.NamespaceConfigResponse{}
|
||||
|
||||
if len(namespaceMap) == 0 {
|
||||
srv.log.Debug("User has no access to any namespaces")
|
||||
return response.JSON(http.StatusOK, result)
|
||||
}
|
||||
|
||||
namespaceUIDs := make([]string, len(namespaceMap))
|
||||
for k := range namespaceMap {
|
||||
@@ -215,7 +221,6 @@ func (srv RulerSrv) RouteGetRulesConfig(c *models.ReqContext) response.Response
|
||||
}
|
||||
}
|
||||
|
||||
result := apimodels.NamespaceConfigResponse{}
|
||||
for namespace, m := range configs {
|
||||
for _, ruleGroupConfig := range m {
|
||||
result[namespace] = append(result[namespace], ruleGroupConfig)
|
||||
|
||||
Reference in New Issue
Block a user