AccessControl: Resolve attribute based scopes to id based scopes (#40742)

* AccessControl: POC scope attribute resolution

Refactor based on ScopeMutators

test errors and calls to cache

Add comments to tests

Rename logger

Create keywordMutator only once

* AccessControl: Add AttributeScopeResolver registration

Co-authored-by: gamab <gabriel.mabille@grafana.com>

* AccessControl: Add AttributeScopeResolver to datasources

Co-authored-by: gamab <gabriel.mabille@grafana.com>

* Test evaluation with translation

* fix imports

* AccessControl: Test attribute resolver

* Fix trailing white space

* Make ScopeResolver public for enterprise redefine

* Handle wildcard

Co-authored-by: Jguer <joao.guerreiro@grafana.com>

Co-authored-by: jguer <joao.guerreiro@grafana.com>
This commit is contained in:
Gabriel MABILLE
2022-01-18 17:34:35 +01:00
committed by GitHub
co-authored by gamab Jguer
parent 7a622422a9
commit 54280fc9d7
14 changed files with 548 additions and 110 deletions
+4 -3
View File
@@ -1,6 +1,7 @@
package accesscontrol
import (
"context"
"testing"
"github.com/stretchr/testify/assert"
@@ -120,7 +121,7 @@ func TestPermission_Inject(t *testing.T) {
for _, test := range tests {
t.Run(test.desc, func(t *testing.T) {
injected, err := test.evaluator.Inject(test.params)
injected, err := test.evaluator.MutateScopes(context.TODO(), ScopeInjector(test.params))
assert.NoError(t, err)
ok, err := injected.Evaluate(test.permissions)
assert.NoError(t, err)
@@ -233,7 +234,7 @@ func TestAll_Inject(t *testing.T) {
for _, test := range tests {
t.Run(test.desc, func(t *testing.T) {
injected, err := test.evaluator.Inject(test.params)
injected, err := test.evaluator.MutateScopes(context.TODO(), ScopeInjector(test.params))
assert.NoError(t, err)
ok, err := injected.Evaluate(test.permissions)
assert.NoError(t, err)
@@ -344,7 +345,7 @@ func TestAny_Inject(t *testing.T) {
for _, test := range tests {
t.Run(test.desc, func(t *testing.T) {
injected, err := test.evaluator.Inject(test.params)
injected, err := test.evaluator.MutateScopes(context.TODO(), ScopeInjector(test.params))
assert.NoError(t, err)
ok, err := injected.Evaluate(test.permissions)
assert.NoError(t, err)