AccessControl: frontend changes for adding FGAC to licensing (#39484)
* refactor licenseURL function to use context and export permission evaluation fction * remove provisioning file * refactor licenseURL to take in a bool to avoid circular dependencies * remove function for appending nav link, as it was only used once and move the function to create admin node * better argument names * create a function for permission checking * extend permission checking when displaying server stats * enable the use of enterprise access control actions when evaluating permissions * import ordering * move licensing FGAC action definitions to models package to allow access from oss * move evaluatePermissions for routes to context serve * change permission evaluator to take in more permissions * move licensing FGAC actions again to appease wire * avoid index out of bounds issue in case no children are passed in when creating server admin node * simplify syntax for permission checking Co-authored-by: Alex Khomenko <Clarity-89@users.noreply.github.com> * update loading state for server stats * linting * more linting * fix test * fix a frontend test * update "licensing.reports:read" action naming * UI doesn't allow reading only licensing reports and not the rest of licensing info Co-authored-by: Alex Khomenko <Clarity-89@users.noreply.github.com>
This commit is contained in:
@@ -197,8 +197,20 @@ const (
|
||||
|
||||
// Settings scope
|
||||
ScopeSettingsAll = "settings:*"
|
||||
|
||||
// Licensing related actions
|
||||
ActionLicensingRead = "licensing:read"
|
||||
ActionLicensingUpdate = "licensing:update"
|
||||
ActionLicensingDelete = "licensing:delete"
|
||||
ActionLicensingReportsRead = "licensing.reports:read"
|
||||
)
|
||||
|
||||
const RoleGrafanaAdmin = "Grafana Admin"
|
||||
|
||||
const FixedRolePrefix = "fixed:"
|
||||
|
||||
// LicensingPageReaderAccess defines permissions that grant access to the licensing and stats page
|
||||
var LicensingPageReaderAccess = EvalAny(
|
||||
EvalPermission(ActionLicensingRead),
|
||||
EvalPermission(ActionServerStatsRead),
|
||||
)
|
||||
|
||||
@@ -36,8 +36,8 @@ func (*OSSLicensingService) ContentDeliveryPrefix() string {
|
||||
return "grafana-oss"
|
||||
}
|
||||
|
||||
func (l *OSSLicensingService) LicenseURL(user *models.SignedInUser) string {
|
||||
if user.IsGrafanaAdmin {
|
||||
func (l *OSSLicensingService) LicenseURL(showAdminLicensingPage bool) string {
|
||||
if showAdminLicensingPage {
|
||||
return l.Cfg.AppSubURL + "/admin/upgrading"
|
||||
}
|
||||
|
||||
@@ -59,7 +59,7 @@ func ProvideService(cfg *setting.Cfg, hooksService *hooks.HooksService) *OSSLice
|
||||
node.Children = append(node.Children, &dtos.NavLink{
|
||||
Text: "Stats and license",
|
||||
Id: "upgrading",
|
||||
Url: l.LicenseURL(req.SignedInUser),
|
||||
Url: l.LicenseURL(req.IsGrafanaAdmin),
|
||||
Icon: "unlock",
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user