Alerting: Fix folder permissions for Editor role in Prometheus import (#109977)

Alerting: Fix folder permisisons for Editor role in Prometheus import
This commit is contained in:
Alexander Akhmetov
2025-08-22 13:15:53 +02:00
committed by GitHub
parent 33ca5f166f
commit b4ff398865
6 changed files with 87 additions and 13 deletions
@@ -461,7 +461,7 @@ func (srv *ConvertPrometheusSrv) RouteConvertPrometheusPostRuleGroups(c *context
func (srv *ConvertPrometheusSrv) getOrCreateNamespace(c *contextmodel.ReqContext, title string, logger log.Logger, workingFolderUID string) (*folder.FolderReference, response.Response) {
logger.Debug("Getting or creating a new folder")
ns, err := srv.ruleStore.GetOrCreateNamespaceByTitle(
ns, created, err := srv.ruleStore.GetOrCreateNamespaceByTitle(
c.Req.Context(),
title,
c.GetOrgID(),
@@ -473,6 +473,26 @@ func (srv *ConvertPrometheusSrv) getOrCreateNamespace(c *contextmodel.ReqContext
return nil, namespaceErrorResponse(err)
}
// Not all users have global-scoped permissions, even if they can create folders.
// For example, Editor users can create folders, but they have UID-scoped folder permissions.
// Permissions are populated in a middleware before this handler, and the folder we just created
// is not included in the permissions yet. We add it manually.
if created {
orgID := c.GetOrgID()
if c.Permissions == nil {
c.Permissions = make(map[int64]map[string][]string)
}
if c.Permissions[orgID] == nil {
c.Permissions[orgID] = make(map[string][]string)
}
folderScope := dashboards.ScopeFoldersProvider.GetResourceScopeUID(ns.UID)
if c.Permissions[orgID][dashboards.ActionFoldersRead] == nil {
c.Permissions[orgID][dashboards.ActionFoldersRead] = []string{}
}
c.Permissions[orgID][dashboards.ActionFoldersRead] = append(c.Permissions[orgID][dashboards.ActionFoldersRead], folderScope)
}
logger.Debug("Using folder for the converted rules", "folder_uid", ns.UID)
return ns, nil
+1 -1
View File
@@ -16,7 +16,7 @@ type RuleStore interface {
GetUserVisibleNamespaces(context.Context, int64, identity.Requester) (map[string]*folder.Folder, error)
GetNamespaceByUID(ctx context.Context, uid string, orgID int64, user identity.Requester) (*folder.Folder, error)
GetNamespaceByTitle(ctx context.Context, fullpath string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, error)
GetOrCreateNamespaceByTitle(ctx context.Context, title string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, error)
GetOrCreateNamespaceByTitle(ctx context.Context, title string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, bool, error)
// GetNamespaceChildren returns all children (first level) of the namespace with the given id.
GetNamespaceChildren(ctx context.Context, uid string, orgID int64, user identity.Requester) ([]*folder.FolderReference, error)