RBAC: Cover plugin routes (#80578)

* RBAC: Cover plugin routes

* Action instead of ReqAction

* Fix test initializations

* Fix NewPluginProxy call

* Duplicate test to add RBAC checks

* Cover legacy access control as well

* Fix typo

* action -> reqAction

* Add example

Co-authored-by: Andres Martinez Gotor <andres.martinez@grafana.com>

---------

Co-authored-by: Andres Martinez Gotor <andres.martinez@grafana.com>
This commit is contained in:
Gabriel MABILLE
2024-01-17 16:32:23 +01:00
committed by GitHub
co-authored by Andres Martinez Gotor
parent 81a49e8016
commit 6b954165c5
6 changed files with 156 additions and 11 deletions
+3
View File
@@ -364,6 +364,9 @@ schemas: [{
reqSignedIn?: bool
reqRole?: string
// RBAC action the user must have to access the route. i.e. plugin-id.projects:read
reqAction?: string
// For data source plugins. Route headers adds HTTP headers to the
// proxied request.
headers?: [...#Header]
+4 -1
View File
@@ -461,7 +461,10 @@ type Route struct {
// For data source plugins. The route path that is replaced by the
// route URL field when proxying the call.
Path *string `json:"path,omitempty"`
Path *string `json:"path,omitempty"`
// RBAC action the user must have to access the route. i.e. plugin-id.projects:read
ReqAction *string `json:"reqAction,omitempty"`
ReqRole *string `json:"reqRole,omitempty"`
ReqSignedIn *bool `json:"reqSignedIn,omitempty"`
+5
View File
@@ -194,6 +194,7 @@ type Route struct {
Path string `json:"path"`
Method string `json:"method"`
ReqRole org.RoleType `json:"reqRole"`
ReqAction string `json:"reqAction"`
URL string `json:"url"`
URLParams []URLParam `json:"urlParams"`
Headers []Header `json:"headers"`
@@ -203,6 +204,10 @@ type Route struct {
Body json.RawMessage `json:"body"`
}
func (r *Route) RequiresRBACAction() bool {
return r.ReqAction != ""
}
// Header describes an HTTP header that is forwarded with
// the proxied request for a plugin route
type Header struct {