Access Control: Support other attributes than id for resource permissions (#46727)

* Add option to set ResourceAttribute for a permissions service
* Use prefix in access control sql filter to parse scopes
* Use prefix in access control metadata to check access
This commit is contained in:
Karl Persson
2022-03-21 17:58:18 +01:00
committed by GitHub
parent 79f5c7d7a7
commit 7ab1ef8d6e
26 changed files with 363 additions and 288 deletions
@@ -36,7 +36,8 @@ func TestApi_getDescription(t *testing.T) {
{
desc: "should return description",
options: Options{
Resource: "dashboards",
Resource: "dashboards",
ResourceAttribute: "uid",
Assignments: Assignments{
Users: true,
Teams: true,
@@ -64,7 +65,8 @@ func TestApi_getDescription(t *testing.T) {
{
desc: "should only return user assignment",
options: Options{
Resource: "dashboards",
Resource: "dashboards",
ResourceAttribute: "uid",
Assignments: Assignments{
Users: true,
Teams: false,
@@ -90,7 +92,8 @@ func TestApi_getDescription(t *testing.T) {
{
desc: "should return 403 when missing read permission",
options: Options{
Resource: "dashboards",
Resource: "dashboards",
ResourceAttribute: "uid",
Assignments: Assignments{
Users: true,
Teams: false,
@@ -514,7 +517,8 @@ func contextProvider(tc *testContext) web.Handler {
}
var testOptions = Options{
Resource: "dashboards",
Resource: "dashboards",
ResourceAttribute: "id",
Assignments: Assignments{
Users: true,
Teams: true,