Zanzana: Use separate store for each org (#96015)
* Move server init into server package * map store name to id * refactor model loading * pass namespace into reconcilers and collectors * refactor * Extend authz server with Read and Write methods * use new read/write in reconciler * implement server side read and write * Sync permissions for every org * handle namespace in check and list * split read and write * provide conditions * Fix client implementation * fix nil conditions * remove unused client code * use lock for store access * move type translators to common package * fix folder collector * fix store creation * remove unused AuthorizationModelId * fix server tests * fix linter
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
package server
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
openfgav1 "github.com/openfga/api/proto/openfga/v1"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/authz/zanzana/common"
|
||||
authzextv1 "github.com/grafana/grafana/pkg/services/authz/zanzana/proto/v1"
|
||||
)
|
||||
|
||||
func (s *Server) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
|
||||
ctx, span := tracer.Start(ctx, "authzServer.Read")
|
||||
defer span.End()
|
||||
|
||||
storeInf, err := s.getNamespaceStore(ctx, req.Namespace)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
res, err := s.openfga.Read(ctx, &openfgav1.ReadRequest{
|
||||
StoreId: storeInf.Id,
|
||||
TupleKey: &openfgav1.ReadRequestTupleKey{
|
||||
User: req.GetTupleKey().GetUser(),
|
||||
Relation: req.GetTupleKey().GetRelation(),
|
||||
Object: req.GetTupleKey().GetObject(),
|
||||
},
|
||||
PageSize: req.GetPageSize(),
|
||||
ContinuationToken: req.GetContinuationToken(),
|
||||
})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
tuples := make([]*authzextv1.Tuple, 0)
|
||||
for _, t := range res.GetTuples() {
|
||||
tuples = append(tuples, &authzextv1.Tuple{
|
||||
Key: common.ToAuthzExtTupleKey(t.GetKey()),
|
||||
Timestamp: t.GetTimestamp(),
|
||||
})
|
||||
}
|
||||
|
||||
return &authzextv1.ReadResponse{
|
||||
Tuples: tuples,
|
||||
ContinuationToken: res.GetContinuationToken(),
|
||||
}, nil
|
||||
}
|
||||
Reference in New Issue
Block a user