grafana-iam: Implement api level user authorization (#114498)
* OnGoing comment * WIP on the wrapper * Get before Delete * WIP: add an unimplemented storage authorizer * WIP implementing the resource permission authorize * Implement beforeCreate * Create, Delete, Update * List * Use a resource permissions wrapper * Switch the main authorizer to service * Add namespace * Use compile for list * Comment * Remove unecessary comments * fix bug with folder permissions * Implement tests for List * Test get * List test small refactor * Delete test * Reorganize code * imports * Start splitting the tests * test AfterDelete * actually test beforeWrite * Implement tests for wrapper create * Test delete * Test List and Get * Fix List * Remaining tests * simplify * Remove comments * Reorder * Change authorizer to allow access
This commit is contained in:
@@ -782,7 +782,7 @@ func (s *Service) listPermission(ctx context.Context, scopeMap map[string]bool,
|
||||
}
|
||||
|
||||
var res *authzv1.ListResponse
|
||||
if strings.HasPrefix(req.Action, "folders:") {
|
||||
if strings.HasPrefix(req.Action, "folders:") || strings.HasPrefix(req.Action, "folders.permissions:") {
|
||||
res = buildFolderList(scopeMap, tree)
|
||||
} else {
|
||||
res = buildItemList(scopeMap, tree, t.Prefix())
|
||||
|
||||
Reference in New Issue
Block a user