Chore: Add user service method SetUsingOrg and GetSignedInUserWithCacheCtx (#53343)
* Chore: Add user service method SetUsingOrg * Chore: Add user service method GetSignedInUserWithCacheCtx * Use method GetSignedInUserWithCacheCtx from user service * Fix lint after rebase * Fix lint * Fix lint error * roll back some changes * Roll back changes in api and middleware * Add xorm tags to SignedInUser ID fields
This commit is contained in:
@@ -257,10 +257,10 @@ func (r *SQLAnnotationRepo) Find(ctx context.Context, query *annotations.ItemQue
|
||||
}
|
||||
|
||||
func getAccessControlFilter(user *user.SignedInUser) (string, []interface{}, error) {
|
||||
if user == nil || user.Permissions[user.OrgId] == nil {
|
||||
if user == nil || user.Permissions[user.OrgID] == nil {
|
||||
return "", nil, errors.New("missing permissions")
|
||||
}
|
||||
scopes, has := user.Permissions[user.OrgId][ac.ActionAnnotationsRead]
|
||||
scopes, has := user.Permissions[user.OrgID][ac.ActionAnnotationsRead]
|
||||
if !has {
|
||||
return "", nil, errors.New("missing permissions")
|
||||
}
|
||||
|
||||
@@ -28,7 +28,7 @@ func TestIntegrationAnnotations(t *testing.T) {
|
||||
repo := sqlstore.NewSQLAnnotationRepo(sql)
|
||||
|
||||
testUser := &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{
|
||||
1: {
|
||||
accesscontrol.ActionAnnotationsRead: []string{accesscontrol.ScopeAnnotationsAll},
|
||||
@@ -438,8 +438,8 @@ func TestIntegrationAnnotationListingWithRBAC(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
user := &user.SignedInUser{
|
||||
UserId: 1,
|
||||
OrgId: 1,
|
||||
UserID: 1,
|
||||
OrgID: 1,
|
||||
}
|
||||
|
||||
type testStruct struct {
|
||||
|
||||
@@ -119,7 +119,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
ac2cmd := user.CreateUserCommand{Login: "ac2", Email: "ac2@test.com", Name: "ac2 name"}
|
||||
|
||||
ac1, err := sqlStore.CreateUser(context.Background(), ac1cmd)
|
||||
testUser.OrgId = ac1.OrgID
|
||||
testUser.OrgID = ac1.OrgID
|
||||
require.NoError(t, err)
|
||||
_, err = sqlStore.CreateUser(context.Background(), ac2cmd)
|
||||
require.NoError(t, err)
|
||||
@@ -177,7 +177,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
|
||||
t.Run("Can search users", func(t *testing.T) {
|
||||
query := models.SearchUsersQuery{Query: "", SignedInUser: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{
|
||||
1: {accesscontrol.ActionUsersRead: {accesscontrol.ScopeGlobalUsersAll}},
|
||||
},
|
||||
@@ -210,7 +210,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
orgUsersQuery := models.GetOrgUsersQuery{
|
||||
OrgId: ac1.OrgID,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: ac1.OrgID,
|
||||
OrgID: ac1.OrgID,
|
||||
Permissions: map[int64]map[string][]string{ac1.OrgID: {accesscontrol.ActionOrgUsersRead: {accesscontrol.ScopeUsersAll}}},
|
||||
},
|
||||
}
|
||||
@@ -226,7 +226,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, query.Result.Email, "ac2@test.com")
|
||||
require.Equal(t, query.Result.OrgId, ac2.OrgID)
|
||||
require.Equal(t, query.Result.OrgID, ac2.OrgID)
|
||||
require.Equal(t, query.Result.Name, "ac2 name")
|
||||
require.Equal(t, query.Result.Login, "ac2")
|
||||
require.EqualValues(t, query.Result.OrgRole, "Admin")
|
||||
@@ -246,7 +246,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
query := models.GetOrgUsersQuery{
|
||||
OrgId: ac1.OrgID,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: ac1.OrgID,
|
||||
OrgID: ac1.OrgID,
|
||||
Permissions: map[int64]map[string][]string{ac1.OrgID: {accesscontrol.ActionOrgUsersRead: {accesscontrol.ScopeUsersAll}}},
|
||||
},
|
||||
}
|
||||
@@ -262,7 +262,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
OrgId: ac1.OrgID,
|
||||
Query: "ac1",
|
||||
User: &user.SignedInUser{
|
||||
OrgId: ac1.OrgID,
|
||||
OrgID: ac1.OrgID,
|
||||
Permissions: map[int64]map[string][]string{ac1.OrgID: {accesscontrol.ActionOrgUsersRead: {accesscontrol.ScopeUsersAll}}},
|
||||
},
|
||||
}
|
||||
@@ -279,7 +279,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
Query: "ac",
|
||||
Limit: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: ac1.OrgID,
|
||||
OrgID: ac1.OrgID,
|
||||
Permissions: map[int64]map[string][]string{ac1.OrgID: {accesscontrol.ActionOrgUsersRead: {accesscontrol.ScopeUsersAll}}},
|
||||
},
|
||||
}
|
||||
@@ -300,7 +300,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
err := sqlStore.GetSignedInUser(context.Background(), &query)
|
||||
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, query.Result.OrgId, ac1.OrgID)
|
||||
require.Equal(t, query.Result.OrgID, ac1.OrgID)
|
||||
require.Equal(t, query.Result.Email, "ac2@test.com")
|
||||
require.Equal(t, query.Result.Name, "ac2 name")
|
||||
require.Equal(t, query.Result.Login, "ac2")
|
||||
@@ -316,7 +316,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
err = sqlStore.GetSignedInUser(context.Background(), &query)
|
||||
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, query.Result.OrgId, ac2.OrgID)
|
||||
require.Equal(t, query.Result.OrgID, ac2.OrgID)
|
||||
})
|
||||
})
|
||||
|
||||
@@ -364,7 +364,7 @@ func TestIntegrationAccountDataAccess(t *testing.T) {
|
||||
query := models.GetOrgUsersQuery{
|
||||
OrgId: ac1.OrgID,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: ac1.OrgID,
|
||||
OrgID: ac1.OrgID,
|
||||
Permissions: map[int64]map[string][]string{ac1.OrgID: {accesscontrol.ActionOrgUsersRead: {accesscontrol.ScopeUsersAll}}},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -27,7 +27,7 @@ func TestSQLStore_GetOrgUsers(t *testing.T) {
|
||||
query: &models.GetOrgUsersQuery{
|
||||
OrgId: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {ac.ScopeUsersAll}}},
|
||||
},
|
||||
},
|
||||
@@ -38,7 +38,7 @@ func TestSQLStore_GetOrgUsers(t *testing.T) {
|
||||
query: &models.GetOrgUsersQuery{
|
||||
OrgId: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {""}}},
|
||||
},
|
||||
},
|
||||
@@ -49,7 +49,7 @@ func TestSQLStore_GetOrgUsers(t *testing.T) {
|
||||
query: &models.GetOrgUsersQuery{
|
||||
OrgId: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {
|
||||
"users:id:1",
|
||||
"users:id:5",
|
||||
@@ -76,7 +76,7 @@ func TestSQLStore_GetOrgUsers(t *testing.T) {
|
||||
|
||||
if !hasWildcardScope(tt.query.User, ac.ActionOrgUsersRead) {
|
||||
for _, u := range tt.query.Result {
|
||||
assert.Contains(t, tt.query.User.Permissions[tt.query.User.OrgId][ac.ActionOrgUsersRead], fmt.Sprintf("users:id:%d", u.UserId))
|
||||
assert.Contains(t, tt.query.User.Permissions[tt.query.User.OrgID][ac.ActionOrgUsersRead], fmt.Sprintf("users:id:%d", u.UserId))
|
||||
}
|
||||
}
|
||||
})
|
||||
@@ -96,7 +96,7 @@ func TestSQLStore_SearchOrgUsers(t *testing.T) {
|
||||
query: &models.SearchOrgUsersQuery{
|
||||
OrgID: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {ac.ScopeUsersAll}}},
|
||||
},
|
||||
},
|
||||
@@ -107,7 +107,7 @@ func TestSQLStore_SearchOrgUsers(t *testing.T) {
|
||||
query: &models.SearchOrgUsersQuery{
|
||||
OrgID: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {""}}},
|
||||
},
|
||||
},
|
||||
@@ -118,7 +118,7 @@ func TestSQLStore_SearchOrgUsers(t *testing.T) {
|
||||
query: &models.SearchOrgUsersQuery{
|
||||
OrgID: 1,
|
||||
User: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionOrgUsersRead: {
|
||||
"users:id:1",
|
||||
"users:id:5",
|
||||
@@ -141,7 +141,7 @@ func TestSQLStore_SearchOrgUsers(t *testing.T) {
|
||||
|
||||
if !hasWildcardScope(tt.query.User, ac.ActionOrgUsersRead) {
|
||||
for _, u := range tt.query.Result.OrgUsers {
|
||||
assert.Contains(t, tt.query.User.Permissions[tt.query.User.OrgId][ac.ActionOrgUsersRead], fmt.Sprintf("users:id:%d", u.UserId))
|
||||
assert.Contains(t, tt.query.User.Permissions[tt.query.User.OrgID][ac.ActionOrgUsersRead], fmt.Sprintf("users:id:%d", u.UserId))
|
||||
}
|
||||
}
|
||||
})
|
||||
@@ -272,7 +272,7 @@ func seedOrgUsers(t *testing.T, store *SQLStore, numUsers int) {
|
||||
}
|
||||
|
||||
func hasWildcardScope(user *user.SignedInUser, action string) bool {
|
||||
for _, scope := range user.Permissions[user.OrgId][action] {
|
||||
for _, scope := range user.Permissions[user.OrgID][action] {
|
||||
if strings.HasSuffix(scope, ":*") {
|
||||
return true
|
||||
}
|
||||
|
||||
@@ -26,13 +26,13 @@ const (
|
||||
|
||||
func TestBuilder_EqualResults_Basic(t *testing.T) {
|
||||
user := &user.SignedInUser{
|
||||
UserId: 1,
|
||||
OrgId: 1,
|
||||
UserID: 1,
|
||||
OrgID: 1,
|
||||
OrgRole: org.RoleEditor,
|
||||
}
|
||||
|
||||
db := setupTestEnvironment(t)
|
||||
dashIds := createDashboards(t, db, 0, 1, user.OrgId)
|
||||
dashIds := createDashboards(t, db, 0, 1, user.OrgID)
|
||||
require.Len(t, dashIds, 1)
|
||||
|
||||
// create one dashboard in another organization that shouldn't
|
||||
@@ -41,7 +41,7 @@ func TestBuilder_EqualResults_Basic(t *testing.T) {
|
||||
|
||||
builder := &searchstore.Builder{
|
||||
Filters: []interface{}{
|
||||
searchstore.OrgFilter{OrgId: user.OrgId},
|
||||
searchstore.OrgFilter{OrgId: user.OrgID},
|
||||
searchstore.TitleSorter{},
|
||||
},
|
||||
Dialect: db.Dialect,
|
||||
@@ -68,17 +68,17 @@ func TestBuilder_EqualResults_Basic(t *testing.T) {
|
||||
|
||||
func TestBuilder_Pagination(t *testing.T) {
|
||||
user := &user.SignedInUser{
|
||||
UserId: 1,
|
||||
OrgId: 1,
|
||||
UserID: 1,
|
||||
OrgID: 1,
|
||||
OrgRole: org.RoleViewer,
|
||||
}
|
||||
|
||||
db := setupTestEnvironment(t)
|
||||
createDashboards(t, db, 0, 25, user.OrgId)
|
||||
createDashboards(t, db, 0, 25, user.OrgID)
|
||||
|
||||
builder := &searchstore.Builder{
|
||||
Filters: []interface{}{
|
||||
searchstore.OrgFilter{OrgId: user.OrgId},
|
||||
searchstore.OrgFilter{OrgId: user.OrgID},
|
||||
searchstore.TitleSorter{},
|
||||
},
|
||||
Dialect: db.Dialect,
|
||||
@@ -114,25 +114,25 @@ func TestBuilder_Pagination(t *testing.T) {
|
||||
|
||||
func TestBuilder_Permissions(t *testing.T) {
|
||||
user := &user.SignedInUser{
|
||||
UserId: 1,
|
||||
OrgId: 1,
|
||||
UserID: 1,
|
||||
OrgID: 1,
|
||||
OrgRole: org.RoleViewer,
|
||||
}
|
||||
|
||||
db := setupTestEnvironment(t)
|
||||
createDashboards(t, db, 0, 1, user.OrgId)
|
||||
createDashboards(t, db, 0, 1, user.OrgID)
|
||||
|
||||
level := models.PERMISSION_EDIT
|
||||
|
||||
builder := &searchstore.Builder{
|
||||
Filters: []interface{}{
|
||||
searchstore.OrgFilter{OrgId: user.OrgId},
|
||||
searchstore.OrgFilter{OrgId: user.OrgID},
|
||||
searchstore.TitleSorter{},
|
||||
permissions.DashboardPermissionFilter{
|
||||
Dialect: db.Dialect,
|
||||
OrgRole: user.OrgRole,
|
||||
OrgId: user.OrgId,
|
||||
UserId: user.UserId,
|
||||
OrgId: user.OrgID,
|
||||
UserId: user.UserID,
|
||||
PermissionLevel: level,
|
||||
},
|
||||
},
|
||||
|
||||
@@ -51,8 +51,8 @@ func (sb *SQLBuilder) WriteDashboardPermissionFilter(user *user.SignedInUser, pe
|
||||
sql, params = permissions.DashboardPermissionFilter{
|
||||
OrgRole: user.OrgRole,
|
||||
Dialect: dialect,
|
||||
UserId: user.UserId,
|
||||
OrgId: user.OrgId,
|
||||
UserId: user.UserID,
|
||||
OrgId: user.OrgID,
|
||||
PermissionLevel: permission,
|
||||
}.Where()
|
||||
}
|
||||
|
||||
@@ -308,13 +308,13 @@ func getDashboards(t *testing.T, sqlStore *SQLStore, search Search, aclUserID in
|
||||
|
||||
builder := NewSqlBuilder(sqlStore.Cfg)
|
||||
signedInUser := &user.SignedInUser{
|
||||
UserId: 9999999999,
|
||||
UserID: 9999999999,
|
||||
}
|
||||
|
||||
if search.OrgId == 0 {
|
||||
signedInUser.OrgId = 1
|
||||
signedInUser.OrgID = 1
|
||||
} else {
|
||||
signedInUser.OrgId = search.OrgId
|
||||
signedInUser.OrgID = search.OrgId
|
||||
}
|
||||
|
||||
if len(string(search.UsersOrgRole)) > 0 {
|
||||
@@ -323,7 +323,7 @@ func getDashboards(t *testing.T, sqlStore *SQLStore, search Search, aclUserID in
|
||||
signedInUser.OrgRole = org.RoleViewer
|
||||
}
|
||||
if search.UserFromACL {
|
||||
signedInUser.UserId = aclUserID
|
||||
signedInUser.UserID = aclUserID
|
||||
}
|
||||
|
||||
var res []*dashboardResponse
|
||||
|
||||
@@ -33,8 +33,8 @@ type Store interface {
|
||||
SetUsingOrg(ctx context.Context, cmd *models.SetUsingOrgCommand) error
|
||||
GetUserProfile(ctx context.Context, query *models.GetUserProfileQuery) error
|
||||
GetUserOrgList(ctx context.Context, query *models.GetUserOrgListQuery) error
|
||||
GetSignedInUserWithCacheCtx(ctx context.Context, query *models.GetSignedInUserQuery) error
|
||||
GetSignedInUser(ctx context.Context, query *models.GetSignedInUserQuery) error
|
||||
GetSignedInUserWithCacheCtx(ctx context.Context, query *models.GetSignedInUserQuery) error
|
||||
SearchUsers(ctx context.Context, query *models.SearchUsersQuery) error
|
||||
DisableUser(ctx context.Context, cmd *models.DisableUserCommand) error
|
||||
BatchDisableUsers(ctx context.Context, cmd *models.BatchDisableUsersCommand) error
|
||||
|
||||
@@ -595,7 +595,7 @@ func (ss *SQLStore) getTeamMembers(ctx context.Context, query *models.GetTeamMem
|
||||
func (ss *SQLStore) IsAdminOfTeams(ctx context.Context, query *models.IsAdminOfTeamsQuery) error {
|
||||
return ss.WithDbSession(ctx, func(sess *DBSession) error {
|
||||
builder := &SQLBuilder{}
|
||||
builder.Write("SELECT COUNT(team.id) AS count FROM team INNER JOIN team_member ON team_member.team_id = team.id WHERE team.org_id = ? AND team_member.user_id = ? AND team_member.permission = ?", query.SignedInUser.OrgId, query.SignedInUser.UserId, models.PERMISSION_ADMIN)
|
||||
builder.Write("SELECT COUNT(team.id) AS count FROM team INNER JOIN team_member ON team_member.team_id = team.id WHERE team.org_id = ? AND team_member.user_id = ? AND team_member.permission = ?", query.SignedInUser.OrgID, query.SignedInUser.UserID, models.PERMISSION_ADMIN)
|
||||
|
||||
type teamCount struct {
|
||||
Count int64
|
||||
|
||||
@@ -21,7 +21,7 @@ func TestIntegrationTeamCommandsAndQueries(t *testing.T) {
|
||||
t.Run("Testing Team commands & queries", func(t *testing.T) {
|
||||
sqlStore := InitTestDB(t)
|
||||
testUser := &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{
|
||||
1: {
|
||||
ac.ActionTeamsRead: []string{ac.ScopeTeamsAll},
|
||||
@@ -227,7 +227,7 @@ func TestIntegrationTeamCommandsAndQueries(t *testing.T) {
|
||||
OrgId: testOrgID,
|
||||
UserId: userIds[0],
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: testOrgID,
|
||||
OrgID: testOrgID,
|
||||
Permissions: map[int64]map[string][]string{testOrgID: {ac.ActionOrgUsersRead: {ac.ScopeUsersAll}, ac.ActionTeamsRead: {ac.ScopeTeamsAll}}},
|
||||
},
|
||||
}
|
||||
@@ -319,12 +319,12 @@ func TestIntegrationTeamCommandsAndQueries(t *testing.T) {
|
||||
err = sqlStore.AddTeamMember(userIds[1], testOrgID, groupId, false, models.PERMISSION_ADMIN)
|
||||
require.NoError(t, err)
|
||||
|
||||
query := &models.IsAdminOfTeamsQuery{SignedInUser: &user.SignedInUser{OrgId: testOrgID, UserId: userIds[0]}}
|
||||
query := &models.IsAdminOfTeamsQuery{SignedInUser: &user.SignedInUser{OrgID: testOrgID, UserID: userIds[0]}}
|
||||
err = sqlStore.IsAdminOfTeams(context.Background(), query)
|
||||
require.NoError(t, err)
|
||||
require.False(t, query.Result)
|
||||
|
||||
query = &models.IsAdminOfTeamsQuery{SignedInUser: &user.SignedInUser{OrgId: testOrgID, UserId: userIds[1]}}
|
||||
query = &models.IsAdminOfTeamsQuery{SignedInUser: &user.SignedInUser{OrgID: testOrgID, UserID: userIds[1]}}
|
||||
err = sqlStore.IsAdminOfTeams(context.Background(), query)
|
||||
require.NoError(t, err)
|
||||
require.True(t, query.Result)
|
||||
@@ -335,7 +335,7 @@ func TestIntegrationTeamCommandsAndQueries(t *testing.T) {
|
||||
setup()
|
||||
signedInUser := &user.SignedInUser{
|
||||
Login: "loginuser0",
|
||||
OrgId: testOrgID,
|
||||
OrgID: testOrgID,
|
||||
Permissions: map[int64]map[string][]string{
|
||||
testOrgID: {
|
||||
ac.ActionTeamsRead: []string{ac.ScopeTeamsAll},
|
||||
@@ -424,7 +424,7 @@ func TestIntegrationSQLStore_SearchTeams(t *testing.T) {
|
||||
query: &models.SearchTeamsQuery{
|
||||
OrgId: 1,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionTeamsRead: {ac.ScopeTeamsAll}}},
|
||||
},
|
||||
},
|
||||
@@ -435,7 +435,7 @@ func TestIntegrationSQLStore_SearchTeams(t *testing.T) {
|
||||
query: &models.SearchTeamsQuery{
|
||||
OrgId: 1,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionTeamsRead: {""}}},
|
||||
},
|
||||
},
|
||||
@@ -446,7 +446,7 @@ func TestIntegrationSQLStore_SearchTeams(t *testing.T) {
|
||||
query: &models.SearchTeamsQuery{
|
||||
OrgId: 1,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {ac.ActionTeamsRead: {
|
||||
"teams:id:1",
|
||||
"teams:id:5",
|
||||
@@ -475,7 +475,7 @@ func TestIntegrationSQLStore_SearchTeams(t *testing.T) {
|
||||
|
||||
if !hasWildcardScope(tt.query.SignedInUser, ac.ActionTeamsRead) {
|
||||
for _, team := range tt.query.Result.Teams {
|
||||
assert.Contains(t, tt.query.SignedInUser.Permissions[tt.query.SignedInUser.OrgId][ac.ActionTeamsRead], fmt.Sprintf("teams:id:%d", team.Id))
|
||||
assert.Contains(t, tt.query.SignedInUser.Permissions[tt.query.SignedInUser.OrgID][ac.ActionTeamsRead], fmt.Sprintf("teams:id:%d", team.Id))
|
||||
}
|
||||
}
|
||||
})
|
||||
@@ -534,7 +534,7 @@ func TestIntegrationSQLStore_GetTeamMembers_ACFilter(t *testing.T) {
|
||||
query: &models.GetTeamMembersQuery{
|
||||
OrgId: testOrgID,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: testOrgID,
|
||||
OrgID: testOrgID,
|
||||
Permissions: map[int64]map[string][]string{testOrgID: {ac.ActionOrgUsersRead: {ac.ScopeUsersAll}}},
|
||||
},
|
||||
},
|
||||
@@ -545,7 +545,7 @@ func TestIntegrationSQLStore_GetTeamMembers_ACFilter(t *testing.T) {
|
||||
query: &models.GetTeamMembersQuery{
|
||||
OrgId: testOrgID,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: testOrgID,
|
||||
OrgID: testOrgID,
|
||||
Permissions: map[int64]map[string][]string{testOrgID: {ac.ActionOrgUsersRead: {""}}},
|
||||
},
|
||||
},
|
||||
@@ -557,7 +557,7 @@ func TestIntegrationSQLStore_GetTeamMembers_ACFilter(t *testing.T) {
|
||||
query: &models.GetTeamMembersQuery{
|
||||
OrgId: testOrgID,
|
||||
SignedInUser: &user.SignedInUser{
|
||||
OrgId: testOrgID,
|
||||
OrgID: testOrgID,
|
||||
Permissions: map[int64]map[string][]string{testOrgID: {ac.ActionOrgUsersRead: {
|
||||
ac.Scope("users", "id", fmt.Sprintf("%d", userIds[0])),
|
||||
ac.Scope("users", "id", fmt.Sprintf("%d", userIds[2])),
|
||||
@@ -577,7 +577,7 @@ func TestIntegrationSQLStore_GetTeamMembers_ACFilter(t *testing.T) {
|
||||
if !hasWildcardScope(tt.query.SignedInUser, ac.ActionOrgUsersRead) {
|
||||
for _, member := range tt.query.Result {
|
||||
assert.Contains(t,
|
||||
tt.query.SignedInUser.Permissions[tt.query.SignedInUser.OrgId][ac.ActionOrgUsersRead],
|
||||
tt.query.SignedInUser.Permissions[tt.query.SignedInUser.OrgID][ac.ActionOrgUsersRead],
|
||||
ac.Scope("users", "id", fmt.Sprintf("%d", member.UserId)),
|
||||
)
|
||||
}
|
||||
|
||||
@@ -486,7 +486,7 @@ func (ss *SQLStore) GetSignedInUserWithCacheCtx(ctx context.Context, query *mode
|
||||
return err
|
||||
}
|
||||
|
||||
cacheKey = newSignedInUserCacheKey(query.Result.OrgId, query.UserId)
|
||||
cacheKey = newSignedInUserCacheKey(query.Result.OrgID, query.UserId)
|
||||
ss.CacheService.Set(cacheKey, *query.Result, time.Second*5)
|
||||
return nil
|
||||
}
|
||||
@@ -546,26 +546,26 @@ func (ss *SQLStore) GetSignedInUser(ctx context.Context, query *models.GetSigned
|
||||
}
|
||||
|
||||
if usr.OrgRole == "" {
|
||||
usr.OrgId = -1
|
||||
usr.OrgID = -1
|
||||
usr.OrgName = "Org missing"
|
||||
}
|
||||
|
||||
if usr.ExternalAuthModule != "oauth_grafana_com" {
|
||||
usr.ExternalAuthId = ""
|
||||
usr.ExternalAuthID = ""
|
||||
}
|
||||
|
||||
// tempUser is used to retrieve the teams for the signed in user for internal use.
|
||||
tempUser := &user.SignedInUser{
|
||||
OrgId: usr.OrgId,
|
||||
OrgID: usr.OrgID,
|
||||
Permissions: map[int64]map[string][]string{
|
||||
usr.OrgId: {
|
||||
usr.OrgID: {
|
||||
ac.ActionTeamsRead: {ac.ScopeTeamsAll},
|
||||
},
|
||||
},
|
||||
}
|
||||
getTeamsByUserQuery := &models.GetTeamsByUserQuery{
|
||||
OrgId: usr.OrgId,
|
||||
UserId: usr.UserId,
|
||||
OrgId: usr.OrgID,
|
||||
UserId: usr.UserID,
|
||||
SignedInUser: tempUser,
|
||||
}
|
||||
err = ss.GetTeamsByUser(ctx, getTeamsByUserQuery)
|
||||
|
||||
@@ -86,7 +86,7 @@ func TestIntegrationUserDataAccess(t *testing.T) {
|
||||
}
|
||||
ss := InitTestDB(t)
|
||||
usr := &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {"users:read": {"global.users:*"}}},
|
||||
}
|
||||
|
||||
@@ -416,9 +416,9 @@ func TestIntegrationUserDataAccess(t *testing.T) {
|
||||
err = ss.GetSignedInUserWithCacheCtx(context.Background(), query4)
|
||||
require.Nil(t, err)
|
||||
require.NotNil(t, query4.Result)
|
||||
require.Equal(t, query4.Result.OrgId, users[0].OrgID)
|
||||
require.Equal(t, query4.Result.OrgID, users[0].OrgID)
|
||||
|
||||
cacheKey := newSignedInUserCacheKey(query4.Result.OrgId, query4.UserId)
|
||||
cacheKey := newSignedInUserCacheKey(query4.Result.OrgID, query4.UserId)
|
||||
_, found := ss.CacheService.Get(cacheKey)
|
||||
require.True(t, found)
|
||||
|
||||
@@ -466,7 +466,7 @@ func TestIntegrationUserDataAccess(t *testing.T) {
|
||||
})
|
||||
|
||||
testUser := &user.SignedInUser{
|
||||
OrgId: 1,
|
||||
OrgID: 1,
|
||||
Permissions: map[int64]map[string][]string{1: {"users:read": {"global.users:id:1", "global.users:id:3"}}},
|
||||
}
|
||||
query := models.SearchUsersQuery{SignedInUser: testUser}
|
||||
|
||||
Reference in New Issue
Block a user