Auth: Add empty role definition (#64694)
* Allow setting role as None Co-authored-by: gamab <gabi.mabs@gmail.com> Seeking for places where role.None would be used Co-authored-by: Jguer <joao.guerreiro@grafana.com> Adding None role to the frontend Co-authored-by: Jguer <joao.guerreiro@grafana.com> unify org role declaration and remove from add permission fix backend test fix backend lint * remove role none from frontend * Simplify checks Co-authored-by: Kalle Persson <kalle.persson@grafana.com> * nits --------- Co-authored-by: Kalle Persson <kalle.persson@grafana.com>
This commit is contained in:
co-authored by
gamab
Kalle Persson
parent
b6fbf307d9
commit
d6c468c1c2
@@ -8,6 +8,7 @@ import (
|
||||
var (
|
||||
ErrFixedRolePrefixMissing = errors.New("fixed role should be prefixed with '" + FixedRolePrefix + "'")
|
||||
ErrInvalidBuiltinRole = errors.New("built-in role is not valid")
|
||||
ErrNoneRoleAssignment = errors.New("none role cannot receive permissions")
|
||||
ErrInvalidScope = errors.New("invalid scope")
|
||||
ErrResolverNotFound = errors.New("no resolver found")
|
||||
ErrPluginIDRequired = errors.New("plugin ID is required")
|
||||
|
||||
@@ -264,6 +264,9 @@ func ValidateFixedRole(role RoleDTO) error {
|
||||
// ValidateBuiltInRoles errors when a built-in role does not match expected pattern
|
||||
func ValidateBuiltInRoles(builtInRoles []string) error {
|
||||
for _, br := range builtInRoles {
|
||||
if org.RoleType(br) == org.RoleNone {
|
||||
return ErrNoneRoleAssignment
|
||||
}
|
||||
if !org.RoleType(br).IsValid() && br != RoleGrafanaAdmin {
|
||||
return fmt.Errorf("'%s' %w", br, ErrInvalidBuiltinRole)
|
||||
}
|
||||
@@ -327,6 +330,17 @@ func BuildBasicRoleDefinitions() map[string]*RoleDTO {
|
||||
Permissions: []Permission{},
|
||||
Hidden: true,
|
||||
},
|
||||
string(org.RoleNone): {
|
||||
Name: BasicRolePrefix + "none",
|
||||
UID: BasicRoleUIDPrefix + "none",
|
||||
OrgID: GlobalOrgID,
|
||||
Version: 1,
|
||||
DisplayName: string(org.RoleNone),
|
||||
Description: "None role",
|
||||
Group: "Basic",
|
||||
Permissions: []Permission{},
|
||||
Hidden: true,
|
||||
},
|
||||
RoleGrafanaAdmin: {
|
||||
Name: BasicRolePrefix + "grafana_admin",
|
||||
UID: BasicRoleUIDPrefix + "grafana_admin",
|
||||
|
||||
Reference in New Issue
Block a user