grafana-iam: Implement resourcepermission get (#110256)

* resource permissions get

* address review feedback

* address comments
- read using rp name
- narrow by scope and actionsets
- update sql tests

* align with verb simplification

* keep original format to avoid conflicts

* add sqltests

* cleanup

* Remove unecessary errors

* Move query template to queries

* Use splitN to make sure we have three parts

* Revert user permission management for now. We don't need it

* Revert error change

* group permissions by resource

* extract parse scope

* Move sql_test

* Move & test parseScope

* Add tests to getResourcePermission

* Linting

* Use namespace

* Add test to the backend

* Ongoing tests

* Remove pagination, fix query boolean, insert basic role binding

* Linting

* Straightened the created and updated times

* error handling and uniformization with other backend

* Restore comments to avoid later conflicts

* Integration testing

* switch to function, no need to make it a method

* isServiceAccount should default to FALSE instead of TRUE :surprised:

* PR feedback

* Sort spec permissions

* Shouldn't happen but double proofing

---------

Co-authored-by: Gabriel Mabille <gabriel.mabille@grafana.com>
This commit is contained in:
mohammad-hamid
2025-09-04 17:14:15 +02:00
committed by GitHub
co-authored by Gabriel Mabille
parent 40bf167cb7
commit abcdf20105
16 changed files with 1075 additions and 8 deletions
@@ -0,0 +1,30 @@
package resourcepermission
type Mapper interface {
ActionSets() []string
Scope(name string) string
}
type mapper struct {
resource string
actionSets []string
}
func NewMapper(resource string, levels []string) Mapper {
sets := make([]string, 0, len(levels))
for _, level := range levels {
sets = append(sets, resource+":"+level)
}
return mapper{
resource: resource,
actionSets: sets,
}
}
func (m mapper) ActionSets() []string {
return m.actionSets
}
func (m mapper) Scope(name string) string {
return m.resource + ":uid:" + name
}