[v11.3.x] Alerting: Fix per-receiver RBAC for receivers with long names (#95165)
Alerting: Fix per-receiver RBAC for receivers with long names (#95084)
* Implement uidToResourceID
* add middleware
* Move uidToResourceID to alerting package
* Only hash uid if it's too long
* Use hashed uid in access control
* Move ReceiverUidToResourceId to ScopeProvider
* resolve uid in middleware only if param exists
* Tests
* Linting
---------
Co-authored-by: Yuri Tseretyan <yuriy.tseretyan@grafana.com>
(cherry picked from commit 4aad44e848)
Co-authored-by: Matthew Jacobson <matthew.jacobson@grafana.com>
This commit is contained in:
co-authored by
Matthew Jacobson
parent
a6bc76df32
commit
a09dcda92d
@@ -2,10 +2,14 @@ package accesscontrol
|
||||
|
||||
import (
|
||||
"context"
|
||||
// #nosec G505 Used only for shortening the uid, not for security purposes.
|
||||
"crypto/sha1"
|
||||
"encoding/hex"
|
||||
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
ac "github.com/grafana/grafana/pkg/services/accesscontrol"
|
||||
"github.com/grafana/grafana/pkg/services/ngalert/models"
|
||||
"github.com/grafana/grafana/pkg/util"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -13,10 +17,30 @@ const (
|
||||
)
|
||||
|
||||
var (
|
||||
ScopeReceiversProvider = ac.NewScopeProvider(ScopeReceiversRoot)
|
||||
ScopeReceiversProvider = ReceiverScopeProvider{ac.NewScopeProvider(ScopeReceiversRoot)}
|
||||
ScopeReceiversAll = ScopeReceiversProvider.GetResourceAllScope()
|
||||
)
|
||||
|
||||
type ReceiverScopeProvider struct {
|
||||
ac.ScopeProvider
|
||||
}
|
||||
|
||||
func (p ReceiverScopeProvider) GetResourceScopeUID(uid string) string {
|
||||
return ScopeReceiversProvider.ScopeProvider.GetResourceScopeUID(p.GetResourceIDFromUID(uid))
|
||||
}
|
||||
|
||||
// GetResourceIDFromUID converts a receiver uid to a resource id. This is necessary as resource ids are limited to 40 characters.
|
||||
// If the uid is already less than or equal to 40 characters, it is returned as is.
|
||||
func (p ReceiverScopeProvider) GetResourceIDFromUID(uid string) string {
|
||||
if len(uid) <= util.MaxUIDLength {
|
||||
return uid
|
||||
}
|
||||
// #nosec G505 Used only for shortening the uid, not for security purposes.
|
||||
h := sha1.New()
|
||||
h.Write([]byte(uid))
|
||||
return hex.EncodeToString(h.Sum(nil))
|
||||
}
|
||||
|
||||
// ReceiverPermission is a type for representing a receiver permission.
|
||||
type ReceiverPermission string
|
||||
|
||||
|
||||
Reference in New Issue
Block a user