AuthN: Add auth hook that can sync grafana cloud role to rbac cloud role (#80416)

* AuthnSync: Rename files and structures

* AuthnSync: register rbac cloud role sync if feature toggle is enabled

* RBAC: Add new sync function to service interface

* RBAC: add common prefix and role names for cloud fixed roles

* AuthnSync+RBAC: implement rbac cloud role sync

Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
Karl Persson
2024-01-17 10:55:47 +01:00
committed by GitHub
co-authored by Ieva
parent 24c32219bb
commit 7b58f71b33
10 changed files with 286 additions and 111 deletions
+8 -2
View File
@@ -160,10 +160,16 @@ func ProvideService(
s.RegisterPostAuthHook(userSyncService.SyncUserHook, 10)
s.RegisterPostAuthHook(userSyncService.EnableUserHook, 20)
s.RegisterPostAuthHook(orgUserSyncService.SyncOrgRolesHook, 30)
s.RegisterPostAuthHook(userSyncService.SyncLastSeenHook, 120)
s.RegisterPostAuthHook(userSyncService.SyncLastSeenHook, 130)
s.RegisterPostAuthHook(sync.ProvideOAuthTokenSync(oauthTokenService, sessionService, socialService).SyncOauthTokenHook, 60)
s.RegisterPostAuthHook(userSyncService.FetchSyncedUserHook, 100)
s.RegisterPostAuthHook(sync.ProvidePermissionsSync(accessControlService).SyncPermissionsHook, 110)
rbacSync := sync.ProvideRBACSync(accessControlService)
if features.IsEnabledGlobally(featuremgmt.FlagCloudRBACRoles) {
s.RegisterPostAuthHook(rbacSync.SyncCloudRoles, 110)
}
s.RegisterPostAuthHook(rbacSync.SyncPermissionsHook, 120)
return s
}