Service Accounts: Run service account creation in transaction (#94744)
* run service account creation DB queries in transaction * extract the signed in user from the context * undo unneeded change * don't error out if a user is not found * Update pkg/services/serviceaccounts/manager/service.go Co-authored-by: Misi <mgyongyosi@users.noreply.github.com> * Update pkg/services/serviceaccounts/manager/service.go Co-authored-by: Karl Persson <kalle.persson@grafana.com> --------- Co-authored-by: Misi <mgyongyosi@users.noreply.github.com> Co-authored-by: Karl Persson <kalle.persson@grafana.com>
This commit is contained in:
co-authored by
Misi
Karl Persson
parent
cc9881343e
commit
ca1fd028a2
@@ -101,17 +101,6 @@ func (api *ServiceAccountsAPI) CreateServiceAccount(c *contextmodel.ReqContext)
|
||||
|
||||
if api.cfg.RBAC.PermissionsOnCreation("service-account") {
|
||||
if c.SignedInUser.IsIdentityType(claims.TypeUser) {
|
||||
userID, err := c.SignedInUser.GetInternalID()
|
||||
if err != nil {
|
||||
return response.Error(http.StatusInternalServerError, "Failed to parse user id", err)
|
||||
}
|
||||
|
||||
if _, err := api.permissionService.SetUserPermission(c.Req.Context(),
|
||||
c.SignedInUser.GetOrgID(), accesscontrol.User{ID: userID},
|
||||
strconv.FormatInt(serviceAccount.Id, 10), "Admin"); err != nil {
|
||||
return response.Error(http.StatusInternalServerError, "Failed to set permissions for service account creator", err)
|
||||
}
|
||||
|
||||
// Clear permission cache for the user who's created the service account, so that new permissions are fetched for their next call
|
||||
// Required for cases when caller wants to immediately interact with the newly created object
|
||||
api.accesscontrolService.ClearUserPermissionCache(c.SignedInUser)
|
||||
|
||||
Reference in New Issue
Block a user