fix(unified-storage): remove permissions after executing on both stores (#109722)

Signed-off-by: Maicon Costa <maiconscosta@gmail.com>
Co-authored-by: Jean-Philippe Quéméner <jeanphilippe.quemener@grafana.com>
This commit is contained in:
maicon
2025-08-15 15:57:42 +00:00
committed by GitHub
co-authored by Jean-Philippe Quéméner
parent 79f4510260
commit 5270d8e53f
20 changed files with 141 additions and 26 deletions
+12 -6
View File
@@ -589,14 +589,20 @@ func (d *dashboardStore) deleteDashboard(cmd *dashboards.DeleteDashboardCommand,
return err
}
// remove all access control permission with folder scope
err := d.deleteResourcePermissions(sess, dashboard.OrgID, dashboards.ScopeFoldersProvider.GetResourceScopeUID(dashboard.UID))
if err != nil {
return err
// While migrating to unified storage, we might execute commands in both stores, so we delete the permissions
// only when the command is executed on both stores, thus we can skip it here.
if cmd.RemovePermissions {
if err := d.deleteResourcePermissions(sess, dashboard.OrgID, dashboards.ScopeFoldersProvider.GetResourceScopeUID(dashboard.UID)); err != nil {
return err
}
}
} else {
if err := d.deleteResourcePermissions(sess, dashboard.OrgID, ac.GetResourceScopeUID("dashboards", dashboard.UID)); err != nil {
return err
// While migrating to unified storage, we might execute commands in both stores, so we delete the permissions
// only when the command is executed on both stores, thus we can skip it here.
if cmd.RemovePermissions {
if err := d.deleteResourcePermissions(sess, dashboard.OrgID, ac.GetResourceScopeUID("dashboards", dashboard.UID)); err != nil {
return err
}
}
}