Alerting: Fix folder permissions for Editor role in Prometheus import (#109977)
Alerting: Fix folder permisisons for Editor role in Prometheus import
This commit is contained in:
@@ -461,7 +461,7 @@ func (srv *ConvertPrometheusSrv) RouteConvertPrometheusPostRuleGroups(c *context
|
||||
func (srv *ConvertPrometheusSrv) getOrCreateNamespace(c *contextmodel.ReqContext, title string, logger log.Logger, workingFolderUID string) (*folder.FolderReference, response.Response) {
|
||||
logger.Debug("Getting or creating a new folder")
|
||||
|
||||
ns, err := srv.ruleStore.GetOrCreateNamespaceByTitle(
|
||||
ns, created, err := srv.ruleStore.GetOrCreateNamespaceByTitle(
|
||||
c.Req.Context(),
|
||||
title,
|
||||
c.GetOrgID(),
|
||||
@@ -473,6 +473,26 @@ func (srv *ConvertPrometheusSrv) getOrCreateNamespace(c *contextmodel.ReqContext
|
||||
return nil, namespaceErrorResponse(err)
|
||||
}
|
||||
|
||||
// Not all users have global-scoped permissions, even if they can create folders.
|
||||
// For example, Editor users can create folders, but they have UID-scoped folder permissions.
|
||||
// Permissions are populated in a middleware before this handler, and the folder we just created
|
||||
// is not included in the permissions yet. We add it manually.
|
||||
if created {
|
||||
orgID := c.GetOrgID()
|
||||
if c.Permissions == nil {
|
||||
c.Permissions = make(map[int64]map[string][]string)
|
||||
}
|
||||
if c.Permissions[orgID] == nil {
|
||||
c.Permissions[orgID] = make(map[string][]string)
|
||||
}
|
||||
|
||||
folderScope := dashboards.ScopeFoldersProvider.GetResourceScopeUID(ns.UID)
|
||||
if c.Permissions[orgID][dashboards.ActionFoldersRead] == nil {
|
||||
c.Permissions[orgID][dashboards.ActionFoldersRead] = []string{}
|
||||
}
|
||||
c.Permissions[orgID][dashboards.ActionFoldersRead] = append(c.Permissions[orgID][dashboards.ActionFoldersRead], folderScope)
|
||||
}
|
||||
|
||||
logger.Debug("Using folder for the converted rules", "folder_uid", ns.UID)
|
||||
|
||||
return ns, nil
|
||||
|
||||
@@ -16,7 +16,7 @@ type RuleStore interface {
|
||||
GetUserVisibleNamespaces(context.Context, int64, identity.Requester) (map[string]*folder.Folder, error)
|
||||
GetNamespaceByUID(ctx context.Context, uid string, orgID int64, user identity.Requester) (*folder.Folder, error)
|
||||
GetNamespaceByTitle(ctx context.Context, fullpath string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, error)
|
||||
GetOrCreateNamespaceByTitle(ctx context.Context, title string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, error)
|
||||
GetOrCreateNamespaceByTitle(ctx context.Context, title string, orgID int64, user identity.Requester, parentUID string) (*folder.FolderReference, bool, error)
|
||||
// GetNamespaceChildren returns all children (first level) of the namespace with the given id.
|
||||
GetNamespaceChildren(ctx context.Context, uid string, orgID int64, user identity.Requester) ([]*folder.FolderReference, error)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user