[v11.3.x] Alerting: Fix per-receiver RBAC for receivers with long names (#95165)

Alerting: Fix per-receiver RBAC for receivers with long names (#95084)

* Implement uidToResourceID

* add middleware

* Move uidToResourceID to alerting package

* Only hash uid if it's too long

* Use hashed uid in access control

* Move ReceiverUidToResourceId to ScopeProvider

* resolve uid in middleware only if param exists

* Tests

* Linting

---------

Co-authored-by: Yuri Tseretyan <yuriy.tseretyan@grafana.com>
(cherry picked from commit 4aad44e848)

Co-authored-by: Matthew Jacobson <matthew.jacobson@grafana.com>
This commit is contained in:
grafana-delivery-bot[bot]
2024-11-14 13:01:31 -05:00
committed by GitHub
co-authored by Matthew Jacobson
parent a6bc76df32
commit a09dcda92d
5 changed files with 74 additions and 11 deletions
@@ -2,10 +2,14 @@ package accesscontrol
import (
"context"
// #nosec G505 Used only for shortening the uid, not for security purposes.
"crypto/sha1"
"encoding/hex"
"github.com/grafana/grafana/pkg/apimachinery/identity"
ac "github.com/grafana/grafana/pkg/services/accesscontrol"
"github.com/grafana/grafana/pkg/services/ngalert/models"
"github.com/grafana/grafana/pkg/util"
)
const (
@@ -13,10 +17,30 @@ const (
)
var (
ScopeReceiversProvider = ac.NewScopeProvider(ScopeReceiversRoot)
ScopeReceiversProvider = ReceiverScopeProvider{ac.NewScopeProvider(ScopeReceiversRoot)}
ScopeReceiversAll = ScopeReceiversProvider.GetResourceAllScope()
)
type ReceiverScopeProvider struct {
ac.ScopeProvider
}
func (p ReceiverScopeProvider) GetResourceScopeUID(uid string) string {
return ScopeReceiversProvider.ScopeProvider.GetResourceScopeUID(p.GetResourceIDFromUID(uid))
}
// GetResourceIDFromUID converts a receiver uid to a resource id. This is necessary as resource ids are limited to 40 characters.
// If the uid is already less than or equal to 40 characters, it is returned as is.
func (p ReceiverScopeProvider) GetResourceIDFromUID(uid string) string {
if len(uid) <= util.MaxUIDLength {
return uid
}
// #nosec G505 Used only for shortening the uid, not for security purposes.
h := sha1.New()
h.Write([]byte(uid))
return hex.EncodeToString(h.Sum(nil))
}
// ReceiverPermission is a type for representing a receiver permission.
type ReceiverPermission string