K8s: Dashboards: Add fine grained access control checks to /apis (#104347)

---------

Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
Co-authored-by: Gabriel MABILLE <gabriel.mabille@grafana.com>
Co-authored-by: Marco de Abreu <marco.deabreu@grafana.com>
Co-authored-by: Georges Chaudy <chaudyg@gmail.com>
This commit is contained in:
Stephanie Hingtgen
2025-04-23 03:29:05 +01:00
committed by GitHub
co-authored by Ieva Gabriel MABILLE Marco de Abreu Georges Chaudy
parent 410c5ebfb7
commit b887e8aa05
10 changed files with 1647 additions and 34 deletions
@@ -122,11 +122,6 @@ func (a *dashboardSqlAccess) getRows(ctx context.Context, sql *legacysql.LegacyD
rows: rows,
a: a,
history: query.GetHistory,
// This looks up rules from the permissions on a user
canReadDashboard: func(scopes ...string) bool {
return true // ???
},
// accesscontrol.Checker(user, dashboards.ActionDashboardsRead),
}, err
}
@@ -138,8 +133,6 @@ type rowsWrapper struct {
history bool
count int
canReadDashboard func(scopes ...string) bool
// Current
row *dashboardRow
err error
@@ -180,17 +173,6 @@ func (r *rowsWrapper) Next() bool {
}
if r.row != nil {
d := r.row
// Access control checker
scopes := []string{dashboards.ScopeDashboardsProvider.GetResourceScopeUID(d.Dash.Name)}
if d.FolderUID != "" { // Copied from searchV2... not sure the logic is right
scopes = append(scopes, dashboards.ScopeFoldersProvider.GetResourceScopeUID(d.FolderUID))
}
if !r.canReadDashboard(scopes...) {
continue
}
// returns the first visible dashboard
return true
}