RBAC: Remove action set feature toggle (#101959)

* remove action set feature toggle

* don't pass feature toggles to action set service instantiation

* linting

* test fixes and frontend clean-up

* fix test
This commit is contained in:
Ieva
2025-03-13 15:18:23 +00:00
committed by GitHub
parent 6d61196e55
commit 9264431c81
22 changed files with 184 additions and 266 deletions
+14 -33
View File
@@ -2,7 +2,6 @@ package permissions
import (
"bytes"
"context"
"fmt"
"slices"
"strings"
@@ -61,59 +60,41 @@ func NewAccessControlDashboardPermissionFilter(user identity.Requester, permissi
var dashboardActionSets []string
if queryType == searchstore.TypeFolder {
folderAction = dashboards.ActionFoldersRead
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
}
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
if needEdit {
folderAction = dashboards.ActionDashboardsCreate
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:edit", "folders:admin"}
}
folderActionSets = []string{"folders:edit", "folders:admin"}
}
} else if queryType == searchstore.TypeDashboard {
dashboardAction = dashboards.ActionDashboardsRead
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
}
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
if needEdit {
dashboardAction = dashboards.ActionDashboardsWrite
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:edit", "dashboards:admin"}
}
folderActionSets = []string{"folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:edit", "dashboards:admin"}
}
} else if queryType == searchstore.TypeAlertFolder {
folderAction = accesscontrol.ActionAlertingRuleRead
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
}
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
if needEdit {
folderAction = accesscontrol.ActionAlertingRuleCreate
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:edit", "folders:admin"}
}
folderActionSets = []string{"folders:edit", "folders:admin"}
}
} else if queryType == searchstore.TypeAnnotation {
dashboardAction = accesscontrol.ActionAnnotationsRead
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
}
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
} else {
folderAction = dashboards.ActionFoldersRead
dashboardAction = dashboards.ActionDashboardsRead
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
}
folderActionSets = []string{"folders:view", "folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:view", "dashboards:edit", "dashboards:admin"}
if needEdit {
folderAction = dashboards.ActionDashboardsCreate
dashboardAction = dashboards.ActionDashboardsWrite
if features.IsEnabled(context.Background(), featuremgmt.FlagAccessActionSets) {
folderActionSets = []string{"folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:edit", "dashboards:admin"}
}
folderActionSets = []string{"folders:edit", "folders:admin"}
dashboardActionSets = []string{"dashboards:edit", "dashboards:admin"}
}
}
@@ -417,7 +417,7 @@ func TestIntegration_DashboardNestedPermissionFilter(t *testing.T) {
permissions: []accesscontrol.Permission{
{Action: dashboards.ActionDashboardsRead, Scope: dashboards.ScopeFoldersAll},
},
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
features: []any{featuremgmt.FlagNestedFolders},
expectedResult: []string{"dashboard under the root", "dashboard under parent folder", "dashboard under subfolder"},
},
{
@@ -459,7 +459,7 @@ func TestIntegration_DashboardNestedPermissionFilter(t *testing.T) {
})
usr := &user.SignedInUser{OrgID: orgID, OrgRole: org.RoleViewer, Permissions: map[int64]map[string][]string{orgID: accesscontrol.GroupScopesByActionContext(context.Background(), tc.permissions)}}
for _, features := range []featuremgmt.FeatureToggles{featuremgmt.WithFeatures(append(tc.features, featuremgmt.FlagAccessActionSets)...), featuremgmt.WithFeatures(tc.features...), featuremgmt.WithFeatures(append(tc.features, featuremgmt.FlagPermissionsFilterRemoveSubquery)...)} {
for _, features := range []featuremgmt.FeatureToggles{featuremgmt.WithFeatures(tc.features...), featuremgmt.WithFeatures(append(tc.features, featuremgmt.FlagPermissionsFilterRemoveSubquery)...)} {
m := features.GetEnabled(context.Background())
keys := make([]string, 0, len(m))
for k := range m {
@@ -616,20 +616,17 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
permission dashboardaccess.PermissionType
signedInUserPermissions []accesscontrol.Permission
expectedResult []string
features []any
}{
{
desc: "Should not list any dashboards if user has no permissions",
permission: dashboardaccess.PERMISSION_VIEW,
signedInUserPermissions: nil,
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: nil,
},
{
desc: "Should not list any folders if user has no permissions",
permission: dashboardaccess.PERMISSION_VIEW,
signedInUserPermissions: nil,
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: nil,
},
{
@@ -639,7 +636,6 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
signedInUserPermissions: []accesscontrol.Permission{
{Action: dashboards.ActionFoldersRead, Scope: dashboards.ScopeFoldersAll},
},
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: []string{"parent", "subfolder"},
},
{
@@ -649,7 +645,6 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
signedInUserPermissions: []accesscontrol.Permission{
{Action: "folders:view", Scope: "folders:uid:parent", Kind: "folders", Identifier: "parent"},
},
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: []string{"parent", "subfolder"},
},
{
@@ -659,7 +654,6 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
signedInUserPermissions: []accesscontrol.Permission{
{Action: "folders:admin", Scope: "folders:uid:subfolder", Kind: "folders", Identifier: "subfolder"},
},
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: []string{"subfolder"},
},
{
@@ -670,7 +664,6 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
{Action: "folders:edit", Scope: "folders:uid:subfolder", Kind: "folders", Identifier: "subfolder"},
{Action: "folders:view", Scope: "folders:uid:parent", Kind: "folders", Identifier: "parent"},
},
features: []any{featuremgmt.FlagNestedFolders, featuremgmt.FlagAccessActionSets},
expectedResult: []string{"subfolder"},
},
}
@@ -696,7 +689,7 @@ func TestIntegration_DashboardNestedPermissionFilter_WithActionSets(t *testing.T
Scope: "folders:uid:unrelated"})
usr := &user.SignedInUser{OrgID: orgID, OrgRole: org.RoleViewer, Permissions: map[int64]map[string][]string{orgID: accesscontrol.GroupScopesByActionContext(context.Background(), tc.signedInUserPermissions)}}
for _, features := range []featuremgmt.FeatureToggles{featuremgmt.WithFeatures(tc.features...), featuremgmt.WithFeatures(append(tc.features, featuremgmt.FlagPermissionsFilterRemoveSubquery)...)} {
for _, features := range []featuremgmt.FeatureToggles{featuremgmt.WithFeatures(featuremgmt.FlagNestedFolders), featuremgmt.WithFeatures(featuremgmt.FlagNestedFolders, featuremgmt.FlagPermissionsFilterRemoveSubquery)} {
m := features.GetEnabled(context.Background())
keys := make([]string, 0, len(m))
for k := range m {
@@ -153,6 +153,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"dashboards:view",
"dashboards:edit",
"dashboards:admin",
int64(1),
int64(1),
int64(1),
@@ -161,6 +164,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"folders:view",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
0,
@@ -168,6 +174,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"folders:read",
"folders:view",
"folders:edit",
"folders:admin",
},
},
{
@@ -186,6 +195,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:write",
"dashboards:edit",
"dashboards:admin",
int64(1),
int64(1),
int64(1),
@@ -194,6 +205,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:write",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
0,
@@ -201,6 +214,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:create",
"folders:edit",
"folders:admin",
},
},
{
@@ -219,6 +234,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"folders:view",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
int64(1),
@@ -227,6 +245,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"folders:read",
"folders:view",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
int64(1),
@@ -235,6 +256,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"dashboards:view",
"dashboards:edit",
"dashboards:admin",
int64(1),
},
},
@@ -254,6 +278,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"dashboards:view",
"dashboards:edit",
"dashboards:admin",
int64(1),
int64(1),
0,
@@ -261,6 +288,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:read",
"folders:view",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
0,
@@ -268,6 +298,9 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"folders:read",
"folders:view",
"folders:edit",
"folders:admin",
},
},
{
@@ -286,6 +319,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:write",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
int64(1),
@@ -294,6 +329,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:create",
"folders:edit",
"folders:admin",
int64(1),
int64(1),
int64(1),
@@ -302,6 +339,8 @@ func TestBuilder_RBAC(t *testing.T) {
int64(1),
0,
"dashboards:write",
"dashboards:edit",
"dashboards:admin",
},
},
}