Auth: Add SignedIn user interface NamespacedID (#72944)

* wip

* scope active user to 1 org

* remove TODOs

* add render auth namespace

* import cycle fix

* make condition more readable

* convert Evaluate to user Requester

* only use active OrgID for SearchUserPermissions

* add cache key to interface definition

* change final SignedInUsers to interface

* fix api key managed roles fetch

* fix anon auth id parsing

* Update pkg/services/accesscontrol/acimpl/accesscontrol.go

Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>

---------

Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
Jo
2023-08-09 09:35:50 +02:00
committed by GitHub
co-authored by Ieva
parent 144e4887ee
commit bd1a856d33
13 changed files with 128 additions and 55 deletions
+18 -1
View File
@@ -1,9 +1,26 @@
package identity
import "github.com/grafana/grafana/pkg/models/roletype"
const (
NamespaceUser = "user"
NamespaceAPIKey = "api-key"
NamespaceServiceAccount = "service-account"
NamespaceAnonymous = "anonymous"
NamespaceRenderService = "render"
)
type Requester interface {
GetIsGrafanaAdmin() bool
GetLogin() string
GetOrgID() int64
GetPermissions(orgID int64) map[string][]string
GetPermissions() map[string][]string
GetTeams() []int64
GetOrgRole() roletype.RoleType
GetNamespacedID() (string, string)
IsNil() bool
// Legacy
GetCacheKey() (string, error)
HasUniqueId() bool
}