RBAC: Change annotation filter to use dashboard based annotation scopes (#78635)
change annotation filter to use dash based annotation scopes
This commit is contained in:
@@ -369,11 +369,11 @@ func (r *xormRepositoryImpl) Get(ctx context.Context, query *annotations.ItemQue
|
||||
func (r *xormRepositoryImpl) getAccessControlFilter(user identity.Requester, accessResources *accesscontrol.AccessResources) (string, error) {
|
||||
var filters []string
|
||||
|
||||
if _, has := accessResources.ScopeTypes[annotations.Organization.String()]; has {
|
||||
if accessResources.CanAccessOrgAnnotations {
|
||||
filters = append(filters, "a.dashboard_id = 0")
|
||||
}
|
||||
|
||||
if _, has := accessResources.ScopeTypes[annotations.Dashboard.String()]; has {
|
||||
if accessResources.CanAccessDashAnnotations {
|
||||
var dashboardIDs []int64
|
||||
for _, id := range accessResources.Dashboards {
|
||||
dashboardIDs = append(dashboardIDs, id)
|
||||
|
||||
@@ -6,11 +6,6 @@ import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/annotations/testutil"
|
||||
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
||||
|
||||
annotation_ac "github.com/grafana/grafana/pkg/services/annotations/accesscontrol"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
@@ -19,7 +14,10 @@ import (
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/services/accesscontrol"
|
||||
"github.com/grafana/grafana/pkg/services/annotations"
|
||||
annotation_ac "github.com/grafana/grafana/pkg/services/annotations/accesscontrol"
|
||||
"github.com/grafana/grafana/pkg/services/annotations/testutil"
|
||||
"github.com/grafana/grafana/pkg/services/dashboards"
|
||||
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
||||
"github.com/grafana/grafana/pkg/services/sqlstore"
|
||||
"github.com/grafana/grafana/pkg/services/tag"
|
||||
"github.com/grafana/grafana/pkg/services/tag/tagimpl"
|
||||
@@ -27,11 +25,6 @@ import (
|
||||
"github.com/grafana/grafana/pkg/setting"
|
||||
)
|
||||
|
||||
var (
|
||||
dashScopeType = annotations.Dashboard.String()
|
||||
orgScopeType = annotations.Organization.String()
|
||||
)
|
||||
|
||||
func TestIntegrationAnnotations(t *testing.T) {
|
||||
if testing.Short() {
|
||||
t.Skip("skipping integration test")
|
||||
@@ -150,7 +143,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
Dashboards: map[string]int64{
|
||||
dashboard.UID: dashboard.ID,
|
||||
},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
CanAccessDashAnnotations: true,
|
||||
})
|
||||
|
||||
require.NoError(t, err)
|
||||
@@ -190,7 +183,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
require.NoError(t, err)
|
||||
query := &annotations.ItemQuery{OrgID: 100, SignedInUser: testUser}
|
||||
accRes := &annotation_ac.AccessResources{ScopeTypes: map[any]struct{}{orgScopeType: {}}}
|
||||
accRes := &annotation_ac.AccessResources{CanAccessOrgAnnotations: true}
|
||||
inserted, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
assert.Len(t, inserted, count)
|
||||
@@ -217,7 +210,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
require.NoError(t, err)
|
||||
query := &annotations.ItemQuery{OrgID: 101, SignedInUser: testUser}
|
||||
accRes := &annotation_ac.AccessResources{ScopeTypes: map[any]struct{}{orgScopeType: {}}}
|
||||
accRes := &annotation_ac.AccessResources{CanAccessOrgAnnotations: true}
|
||||
inserted, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
assert.Len(t, inserted, count)
|
||||
@@ -232,7 +225,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
Dashboards: map[string]int64{
|
||||
dashboard2.UID: dashboard2.ID,
|
||||
},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
CanAccessDashAnnotations: true,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
assert.Len(t, items, 1)
|
||||
@@ -241,8 +234,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
t.Run("Should not find any when item is outside time range", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
@@ -257,8 +250,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
t.Run("Should not find one when tag filter does not match", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
@@ -274,8 +267,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
t.Run("Should not find one when type filter does not match", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
@@ -291,8 +284,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
t.Run("Should find one when all tag filters does match", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
@@ -307,7 +300,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("Should find two annotations using partial match", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{ScopeTypes: map[any]struct{}{orgScopeType: {}}}
|
||||
accRes := &annotation_ac.AccessResources{CanAccessOrgAnnotations: true}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
From: 1,
|
||||
@@ -322,8 +315,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
|
||||
t.Run("Should find one when all key value tag filters does match", func(t *testing.T) {
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), &annotations.ItemQuery{
|
||||
OrgID: 1,
|
||||
@@ -346,8 +339,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
SignedInUser: testUser,
|
||||
}
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
@@ -381,8 +374,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
SignedInUser: testUser,
|
||||
}
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
@@ -414,8 +407,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
SignedInUser: testUser,
|
||||
}
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
@@ -447,8 +440,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
SignedInUser: testUser,
|
||||
}
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
@@ -483,8 +476,8 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
SignedInUser: testUser,
|
||||
}
|
||||
accRes := &annotation_ac.AccessResources{
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
Dashboards: map[string]int64{"foo": 1},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
items, err := store.Get(context.Background(), query, accRes)
|
||||
require.NoError(t, err)
|
||||
@@ -516,7 +509,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
Dashboards: map[string]int64{
|
||||
dashboard2.UID: dashboard2.ID,
|
||||
},
|
||||
ScopeTypes: map[any]struct{}{dashScopeType: {}},
|
||||
CanAccessDashAnnotations: true,
|
||||
}
|
||||
|
||||
query := &annotations.ItemQuery{
|
||||
|
||||
Reference in New Issue
Block a user