[v10.2.x] Bug fix: Correctly set permissions on provisioned dashboards (#77230)
* Bug fix: Correctly set permissions on provisioned dashboards (#77155)
* set default basic role permissions for dashboards even if dash creator permissions can't be set
* temporarily increase the test threshold until we can tweak the page
(cherry picked from commit f6e2a775d3)
* Fix error handling typo
---------
Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
co-authored by
Ieva
parent
d0f037c016
commit
bc34247d8b
+2
-1
@@ -33,7 +33,8 @@ var dashboardSettings = [
|
|||||||
url: '${HOST}/d/O6f11TZWk/panel-tests-bar-gauge?orgId=1&editview=permissions',
|
url: '${HOST}/d/O6f11TZWk/panel-tests-bar-gauge?orgId=1&editview=permissions',
|
||||||
wait: 500,
|
wait: 500,
|
||||||
rootElement: '.main-view',
|
rootElement: '.main-view',
|
||||||
threshold: 9,
|
// TODO: improve the accessibility of the permission tab https://github.com/grafana/grafana/issues/77203
|
||||||
|
threshold: 11,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
url: '${HOST}/d/O6f11TZWk/panel-tests-bar-gauge?orgId=1&editview=dashboard_json',
|
url: '${HOST}/d/O6f11TZWk/panel-tests-bar-gauge?orgId=1&editview=dashboard_json',
|
||||||
|
|||||||
@@ -316,10 +316,7 @@ func (dr *DashboardServiceImpl) SaveProvisionedDashboard(ctx context.Context, dt
|
|||||||
}
|
}
|
||||||
|
|
||||||
if dto.Dashboard.ID == 0 {
|
if dto.Dashboard.ID == 0 {
|
||||||
if err := dr.setDefaultPermissions(ctx, dto, dash, true); err != nil {
|
dr.setDefaultPermissions(ctx, dto, dash, true)
|
||||||
namespaceID, userID := dto.User.GetNamespacedID()
|
|
||||||
dr.log.Error("Could not make user admin", "dashboard", dash.Title, "namespaceID", namespaceID, "userID", userID, "error", err)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return dash, nil
|
return dash, nil
|
||||||
@@ -357,10 +354,7 @@ func (dr *DashboardServiceImpl) SaveFolderForProvisionedDashboards(ctx context.C
|
|||||||
}
|
}
|
||||||
|
|
||||||
if dto.Dashboard.ID == 0 {
|
if dto.Dashboard.ID == 0 {
|
||||||
if err := dr.setDefaultPermissions(ctx, dto, dash, true); err != nil {
|
dr.setDefaultPermissions(ctx, dto, dash, true)
|
||||||
namespaceID, userID := dto.User.GetNamespacedID()
|
|
||||||
dr.log.Error("Could not make user admin", "dashboard", dash.Title, "namespaceID", namespaceID, "userID", userID, "error", err)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return dash, nil
|
return dash, nil
|
||||||
@@ -406,10 +400,7 @@ func (dr *DashboardServiceImpl) SaveDashboard(ctx context.Context, dto *dashboar
|
|||||||
|
|
||||||
// new dashboard created
|
// new dashboard created
|
||||||
if dto.Dashboard.ID == 0 {
|
if dto.Dashboard.ID == 0 {
|
||||||
if err := dr.setDefaultPermissions(ctx, dto, dash, false); err != nil {
|
dr.setDefaultPermissions(ctx, dto, dash, false)
|
||||||
namespaceID, userID := dto.User.GetNamespacedID()
|
|
||||||
dr.log.Error("Could not make user admin", "dashboard", dash.Title, "namespaceID", namespaceID, "userID", userID, "error", err)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return dash, nil
|
return dash, nil
|
||||||
@@ -464,10 +455,7 @@ func (dr *DashboardServiceImpl) ImportDashboard(ctx context.Context, dto *dashbo
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := dr.setDefaultPermissions(ctx, dto, dash, false); err != nil {
|
dr.setDefaultPermissions(ctx, dto, dash, false)
|
||||||
namespaceID, userID := dto.User.GetNamespacedID()
|
|
||||||
dr.log.Error("Could not make user admin", "dashboard", dash.Title, "namespaceID", namespaceID, "userID", userID, "error", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return dash, nil
|
return dash, nil
|
||||||
}
|
}
|
||||||
@@ -482,21 +470,21 @@ func (dr *DashboardServiceImpl) GetDashboardsByPluginID(ctx context.Context, que
|
|||||||
return dr.dashboardStore.GetDashboardsByPluginID(ctx, query)
|
return dr.dashboardStore.GetDashboardsByPluginID(ctx, query)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (dr *DashboardServiceImpl) setDefaultPermissions(ctx context.Context, dto *dashboards.SaveDashboardDTO, dash *dashboards.Dashboard, provisioned bool) error {
|
func (dr *DashboardServiceImpl) setDefaultPermissions(ctx context.Context, dto *dashboards.SaveDashboardDTO, dash *dashboards.Dashboard, provisioned bool) {
|
||||||
inFolder := dash.FolderID > 0
|
inFolder := dash.FolderID > 0
|
||||||
var permissions []accesscontrol.SetResourcePermissionCommand
|
var permissions []accesscontrol.SetResourcePermissionCommand
|
||||||
|
|
||||||
namespaceID, userIDstr := dto.User.GetNamespacedID()
|
if !provisioned {
|
||||||
userID, err := identity.IntIdentifier(namespaceID, userIDstr)
|
namespaceID, userIDstr := dto.User.GetNamespacedID()
|
||||||
|
userID, err := identity.IntIdentifier(namespaceID, userIDstr)
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
dr.log.Error("Could not make user admin", "dashboard", dash.Title, "namespaceID", namespaceID, "userID", userID, "error", err)
|
||||||
}
|
} else if namespaceID == identity.NamespaceUser && userID > 0 {
|
||||||
|
permissions = append(permissions, accesscontrol.SetResourcePermissionCommand{
|
||||||
if !provisioned && namespaceID == identity.NamespaceUser {
|
UserID: userID, Permission: dashboards.PERMISSION_ADMIN.String(),
|
||||||
permissions = append(permissions, accesscontrol.SetResourcePermissionCommand{
|
})
|
||||||
UserID: userID, Permission: dashboards.PERMISSION_ADMIN.String(),
|
}
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if !inFolder {
|
if !inFolder {
|
||||||
@@ -511,12 +499,9 @@ func (dr *DashboardServiceImpl) setDefaultPermissions(ctx context.Context, dto *
|
|||||||
svc = dr.folderPermissions
|
svc = dr.folderPermissions
|
||||||
}
|
}
|
||||||
|
|
||||||
_, err = svc.SetPermissions(ctx, dto.OrgID, dash.UID, permissions...)
|
if _, err := svc.SetPermissions(ctx, dto.OrgID, dash.UID, permissions...); err != nil {
|
||||||
if err != nil {
|
dr.log.Error("Could not set default permissions", "dashboard", dash.Title, "error", err)
|
||||||
return err
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (dr *DashboardServiceImpl) GetDashboard(ctx context.Context, query *dashboards.GetDashboardQuery) (*dashboards.Dashboard, error) {
|
func (dr *DashboardServiceImpl) GetDashboard(ctx context.Context, query *dashboards.GetDashboardQuery) (*dashboards.Dashboard, error) {
|
||||||
|
|||||||
Reference in New Issue
Block a user