Access control: use uid for dashboard and folder scopes (#46807)
* use uid:s for folder and dashboard permissions * evaluate folder and dashboard permissions based on uids * add dashboard.uid to accept list * Check for exact suffix * Check parent folder on create * update test * drop dashboard:create actions with dashboard scope * fix typo * AccessControl: test id 0 scope conversion * AccessControl: store only parent folder UID * AccessControl: extract general as a constant * FolderServices: Prevent creation of a folder uid'd general * FolderServices: Test folder creation prevention * Update pkg/services/guardian/accesscontrol_guardian.go * FolderServices: fix mock call expect * FolderServices: remove uneeded mocks Co-authored-by: jguer <joao.guerreiro@grafana.com>
This commit is contained in:
@@ -241,7 +241,8 @@ type SetResourcePermissionCommand struct {
|
||||
}
|
||||
|
||||
const (
|
||||
GlobalOrgID = 0
|
||||
GlobalOrgID = 0
|
||||
GeneralFolderUID = "general"
|
||||
|
||||
// Permission actions
|
||||
|
||||
|
||||
Reference in New Issue
Block a user