Zanzana: Fix reconciling role with empty UID (#106045)
This commit is contained in:
@@ -154,8 +154,11 @@ func managedPermissionsCollector(store db.DB, kind string) legacyTupleCollector
|
|||||||
subject = zanzana.NewTupleEntry(zanzana.TypeUser, p.UserUID, "")
|
subject = zanzana.NewTupleEntry(zanzana.TypeUser, p.UserUID, "")
|
||||||
} else if len(p.TeamUID) > 0 {
|
} else if len(p.TeamUID) > 0 {
|
||||||
subject = zanzana.NewTupleEntry(zanzana.TypeTeam, p.TeamUID, zanzana.RelationTeamMember)
|
subject = zanzana.NewTupleEntry(zanzana.TypeTeam, p.TeamUID, zanzana.RelationTeamMember)
|
||||||
} else {
|
} else if len(p.BasicRoleName) > 0 {
|
||||||
subject = zanzana.NewTupleEntry(zanzana.TypeRole, zanzana.TranslateBasicRole(p.BasicRoleName), zanzana.RelationAssignee)
|
subject = zanzana.NewTupleEntry(zanzana.TypeRole, zanzana.TranslateBasicRole(p.BasicRoleName), zanzana.RelationAssignee)
|
||||||
|
} else {
|
||||||
|
reconcilerLogger.Debug("unrecognized permission", "permission", p)
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
tuple, ok := zanzana.TranslateToResourceTuple(subject, p.Action, p.Kind, p.Identifier)
|
tuple, ok := zanzana.TranslateToResourceTuple(subject, p.Action, p.Kind, p.Identifier)
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
var tracer = otel.Tracer("github.com/grafana/grafana/pkg/accesscontrol/migrator")
|
var tracer = otel.Tracer("github.com/grafana/grafana/pkg/accesscontrol/migrator")
|
||||||
|
var reconcilerLogger = log.New("zanzana.reconciler")
|
||||||
|
|
||||||
// ZanzanaReconciler is a component to reconcile RBAC permissions to zanzana.
|
// ZanzanaReconciler is a component to reconcile RBAC permissions to zanzana.
|
||||||
// We should rewrite the migration after we have "migrated" all possible actions
|
// We should rewrite the migration after we have "migrated" all possible actions
|
||||||
@@ -40,7 +41,7 @@ type ZanzanaReconciler struct {
|
|||||||
func ProvideZanzanaReconciler(cfg *setting.Cfg, features featuremgmt.FeatureToggles, client zanzana.Client, store db.DB, lock *serverlock.ServerLockService, folderService folder.Service) *ZanzanaReconciler {
|
func ProvideZanzanaReconciler(cfg *setting.Cfg, features featuremgmt.FeatureToggles, client zanzana.Client, store db.DB, lock *serverlock.ServerLockService, folderService folder.Service) *ZanzanaReconciler {
|
||||||
zanzanaReconciler := &ZanzanaReconciler{
|
zanzanaReconciler := &ZanzanaReconciler{
|
||||||
cfg: cfg,
|
cfg: cfg,
|
||||||
log: log.New("zanzana.reconciler"),
|
log: reconcilerLogger,
|
||||||
features: features,
|
features: features,
|
||||||
client: client,
|
client: client,
|
||||||
lock: lock,
|
lock: lock,
|
||||||
|
|||||||
Reference in New Issue
Block a user