fix: bug where disabled didnt disable the use of service account (#47688) (#47725)

(cherry picked from commit 673a2ab49e)

Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com>
This commit is contained in:
Grot (@grafanabot)
2022-04-13 18:47:08 +02:00
committed by GitHub
co-authored by Eric Leijonmarck
parent 67d42fc51c
commit 5332a2db05
3 changed files with 15 additions and 6 deletions
+1
View File
@@ -182,6 +182,7 @@ type SignedInUser struct {
OrgCount int OrgCount int
IsGrafanaAdmin bool IsGrafanaAdmin bool
IsAnonymous bool IsAnonymous bool
IsDisabled bool
HelpFlags1 HelpFlags1 HelpFlags1 HelpFlags1
LastSeenAt time.Time LastSeenAt time.Time
Teams []int64 Teams []int64
+13 -6
View File
@@ -4,6 +4,7 @@ package contexthandler
import ( import (
"context" "context"
"errors" "errors"
"net/http"
"net/url" "net/url"
"strconv" "strconv"
"strings" "strings"
@@ -254,20 +255,26 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
//There is a service account attached to the API key //There is a service account attached to the API key
//Use service account linked to API key as the signed in user //Use service account linked to API key as the signed in user
query := models.GetSignedInUserQuery{UserId: *apikey.ServiceAccountId, OrgId: apikey.OrgId} querySignedInUser := models.GetSignedInUserQuery{UserId: *apikey.ServiceAccountId, OrgId: apikey.OrgId}
if err := h.SQLStore.GetSignedInUserWithCacheCtx(reqContext.Req.Context(), &query); err != nil { if err := h.SQLStore.GetSignedInUserWithCacheCtx(reqContext.Req.Context(), &querySignedInUser); err != nil {
reqContext.Logger.Error( reqContext.Logger.Error(
"Failed to link API key to service account in", "Failed to link API key to service account in",
"id", query.UserId, "id", querySignedInUser.UserId,
"org", query.OrgId, "org", querySignedInUser.OrgId,
"err", err, "err", err,
) )
reqContext.JsonApiErr(500, "Unable to link API key to service account", err) reqContext.JsonApiErr(http.StatusInternalServerError, "Unable to link API key to service account", err)
return true
}
// disabled service accounts are not allowed to access the API
if querySignedInUser.Result.IsDisabled {
reqContext.JsonApiErr(http.StatusUnauthorized, "Service account is disabled", nil)
return true return true
} }
reqContext.IsSignedIn = true reqContext.IsSignedIn = true
reqContext.SignedInUser = query.Result reqContext.SignedInUser = querySignedInUser.Result
return true return true
} }
+1
View File
@@ -535,6 +535,7 @@ func (ss *SQLStore) GetSignedInUser(ctx context.Context, query *models.GetSigned
u.email as email, u.email as email,
u.login as login, u.login as login,
u.name as name, u.name as name,
u.is_disabled as is_disabled,
u.help_flags1 as help_flags1, u.help_flags1 as help_flags1,
u.last_seen_at as last_seen_at, u.last_seen_at as last_seen_at,
(SELECT COUNT(*) FROM org_user where org_user.user_id = u.id) as org_count, (SELECT COUNT(*) FROM org_user where org_user.user_id = u.id) as org_count,