AuthN: Add auth hook that can sync grafana cloud role to rbac cloud role (#80416)
* AuthnSync: Rename files and structures * AuthnSync: register rbac cloud role sync if feature toggle is enabled * RBAC: Add new sync function to service interface * RBAC: add common prefix and role names for cloud fixed roles * AuthnSync+RBAC: implement rbac cloud role sync Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
@@ -40,6 +40,8 @@ type Service interface {
|
||||
SaveExternalServiceRole(ctx context.Context, cmd SaveExternalServiceRoleCommand) error
|
||||
// DeleteExternalServiceRole removes an external service's role and its assignment.
|
||||
DeleteExternalServiceRole(ctx context.Context, externalServiceID string) error
|
||||
// SyncUserRoles adds provided roles to user
|
||||
SyncUserRoles(ctx context.Context, orgID int64, cmd SyncUserRolesCommand) error
|
||||
}
|
||||
|
||||
type RoleRegistry interface {
|
||||
@@ -58,6 +60,14 @@ type SearchOptions struct {
|
||||
UserID int64 // ID for the user for which to return information, if none is specified information is returned for all users.
|
||||
}
|
||||
|
||||
type SyncUserRolesCommand struct {
|
||||
UserID int64
|
||||
// name of roles the user should have
|
||||
RolesToAdd []string
|
||||
// name of roles the user should not have
|
||||
RolesToRemove []string
|
||||
}
|
||||
|
||||
type TeamPermissionsService interface {
|
||||
GetPermissions(ctx context.Context, user identity.Requester, resourceID string) ([]ResourcePermission, error)
|
||||
SetUserPermission(ctx context.Context, orgID int64, user User, resourceID, permission string) (*ResourcePermission, error)
|
||||
|
||||
Reference in New Issue
Block a user