diff --git a/pkg/registry/apis/iam/serviceaccount/validate.go b/pkg/registry/apis/iam/serviceaccount/validate.go index 34e851461a0..72de42b7f35 100644 --- a/pkg/registry/apis/iam/serviceaccount/validate.go +++ b/pkg/registry/apis/iam/serviceaccount/validate.go @@ -51,7 +51,7 @@ func ValidateOnCreate(ctx context.Context, obj *iamv0alpha1.ServiceAccount) erro if !requester.HasRole(requestedRole) { return apierrors.NewForbidden(iamv0alpha1.ServiceAccountResourceInfo.GroupResource(), obj.Name, - fmt.Errorf("can not assign a role higher than user's role")) + fmt.Errorf("cannot assign a role higher than user's role")) } return nil diff --git a/pkg/registry/apis/iam/serviceaccount/validate_test.go b/pkg/registry/apis/iam/serviceaccount/validate_test.go index 39703b83c83..d19aae3f7c8 100644 --- a/pkg/registry/apis/iam/serviceaccount/validate_test.go +++ b/pkg/registry/apis/iam/serviceaccount/validate_test.go @@ -77,7 +77,7 @@ func TestValidateOnCreate(t *testing.T) { OrgRole: identity.RoleViewer, }, expectError: true, - errorContains: "can not assign a role higher than user's role", + errorContains: "cannot assign a role higher than user's role", }, { name: "external service account - valid", diff --git a/pkg/services/authz/rbac/mapper.go b/pkg/services/authz/rbac/mapper.go index 40b42998fbd..950287a1059 100644 --- a/pkg/services/authz/rbac/mapper.go +++ b/pkg/services/authz/rbac/mapper.go @@ -110,7 +110,7 @@ func NewMapperRegistry() MapperRegistry { "folders": newResourceTranslation("folders", "uid", true, false), }, "iam.grafana.app": { - "serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false), + "serviceaccounts": newResourceTranslation("serviceaccounts", "uid", false, true), // Teams is a special case. We translate user permissions from id to uid based. "teams": newResourceTranslation("teams", "uid", false, true), // No need to skip scope on create for roles because we translate `permissions:type:delegate` to `roles:*`` diff --git a/pkg/services/authz/rbac/store/permission_store.go b/pkg/services/authz/rbac/store/permission_store.go index 89eafdde897..20b6e1d1e03 100644 --- a/pkg/services/authz/rbac/store/permission_store.go +++ b/pkg/services/authz/rbac/store/permission_store.go @@ -94,6 +94,10 @@ func (s *SQLPermissionsStore) GetUserPermissions(ctx context.Context, ns types.N if err := res.Scan(&perm.Kind, &perm.Attribute, &perm.Identifier, &perm.Scope); err != nil { return nil, err } + // TODO: Why is the Scope set to '::' when it should be empty in the DB? + if perm.Scope == "::" { + perm.Scope = "" + } perms = append(perms, perm) } diff --git a/pkg/tests/apis/iam/service_account_integration_test.go b/pkg/tests/apis/iam/service_account_integration_test.go index f19be4e81e2..a248b21b387 100644 --- a/pkg/tests/apis/iam/service_account_integration_test.go +++ b/pkg/tests/apis/iam/service_account_integration_test.go @@ -154,9 +154,8 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest }) saClient := helper.GetResourceClient(apis.ResourceClientArgs{ - User: editorWithSACreate, - Namespace: helper.Namespacer(editorWithSACreate.Identity.GetOrgID()), - GVR: gvrServiceAccounts, + User: editorWithSACreate, + GVR: gvrServiceAccounts, }) saToCreate := helper.LoadYAMLOrJSONFile("testdata/serviceaccount-test-higher-role-v0.yaml") @@ -166,7 +165,7 @@ func doServiceAccountCRUDTestsUsingTheNewAPIs(t *testing.T, helper *apis.K8sTest var statusErr *errors.StatusError require.ErrorAs(t, err, &statusErr) require.Equal(t, int32(403), statusErr.ErrStatus.Code) - require.Contains(t, statusErr.ErrStatus.Message, "can not assign a role higher than user's role") + require.Contains(t, statusErr.ErrStatus.Message, "cannot assign a role higher than user's role") }) t.Run("should not be able to create service account without a title", func(t *testing.T) {