From f0d260ba5bfb288fa1b921b7657f67f91c2729f7 Mon Sep 17 00:00:00 2001 From: Ieva Date: Fri, 7 Mar 2025 11:38:15 +0000 Subject: [PATCH] Service Accounts: Don't show error pop-ups for Service Account and Renderer UI flows (#101679) don't show error pop-ups for SAs and renderer --- pkg/api/user.go | 18 ++++++++++-------- public/app/core/services/backend_srv.ts | 9 +++++++++ 2 files changed, 19 insertions(+), 8 deletions(-) diff --git a/pkg/api/user.go b/pkg/api/user.go index 1fab0727d7d..22e92e59e7a 100644 --- a/pkg/api/user.go +++ b/pkg/api/user.go @@ -149,7 +149,7 @@ func (hs *HTTPServer) UpdateSignedInUser(c *contextmodel.ReqContext) response.Re cmd.Email = strings.TrimSpace(cmd.Email) cmd.Login = strings.TrimSpace(cmd.Login) - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -349,7 +349,7 @@ func (hs *HTTPServer) UpdateUserEmail(c *contextmodel.ReqContext) response.Respo // 403: forbiddenError // 500: internalServerError func (hs *HTTPServer) GetSignedInUserOrgList(c *contextmodel.ReqContext) response.Response { - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -369,7 +369,7 @@ func (hs *HTTPServer) GetSignedInUserOrgList(c *contextmodel.ReqContext) respons // 403: forbiddenError // 500: internalServerError func (hs *HTTPServer) GetSignedInUserTeamList(c *contextmodel.ReqContext) response.Response { - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -479,7 +479,7 @@ func (hs *HTTPServer) UserSetUsingOrg(c *contextmodel.ReqContext) response.Respo return response.Error(http.StatusBadRequest, "id is invalid", err) } - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -504,6 +504,7 @@ func (hs *HTTPServer) ChangeActiveOrgAndRedirectToHome(c *contextmodel.ReqContex } if !c.SignedInUser.IsIdentityType(claims.TypeUser) { + hs.log.Debug("Requested endpoint only available to users") c.JsonApiErr(http.StatusForbidden, "Endpoint only available for users", nil) return } @@ -548,7 +549,7 @@ func (hs *HTTPServer) ChangeUserPassword(c *contextmodel.ReqContext) response.Re return response.Error(http.StatusBadRequest, "bad request data", err) } - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -584,7 +585,7 @@ func (hs *HTTPServer) SetHelpFlag(c *contextmodel.ReqContext) response.Response return response.Error(http.StatusBadRequest, "id is invalid", err) } - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -614,7 +615,7 @@ func (hs *HTTPServer) SetHelpFlag(c *contextmodel.ReqContext) response.Response // 403: forbiddenError // 500: internalServerError func (hs *HTTPServer) ClearHelpFlags(c *contextmodel.ReqContext) response.Response { - userID, errResponse := getUserID(c) + userID, errResponse := hs.getUserID(c) if errResponse != nil { return errResponse } @@ -627,8 +628,9 @@ func (hs *HTTPServer) ClearHelpFlags(c *contextmodel.ReqContext) response.Respon return response.JSON(http.StatusOK, &util.DynMap{"message": "Help flag set", "helpFlags1": flags}) } -func getUserID(c *contextmodel.ReqContext) (int64, *response.NormalResponse) { +func (hs *HTTPServer) getUserID(c *contextmodel.ReqContext) (int64, *response.NormalResponse) { if !c.SignedInUser.IsIdentityType(claims.TypeUser) { + hs.log.Debug("Requested endpoint only available to users") return 0, response.Error(http.StatusForbidden, "Endpoint only available for users", nil) } diff --git a/public/app/core/services/backend_srv.ts b/public/app/core/services/backend_srv.ts index cc667ac6c56..3f2c645a300 100644 --- a/public/app/core/services/backend_srv.ts +++ b/public/app/core/services/backend_srv.ts @@ -347,6 +347,15 @@ export class BackendSrv implements BackendService { } showErrorAlert(config: BackendSrvRequest, err: FetchError) { + // do not show error alerts for api keys or render tokens, they are used for kiosk mode and reporting and can't react to error pop-ups + if ( + this.dependencies.contextSrv.isSignedIn && + (this.dependencies.contextSrv.user.authenticatedBy === 'apikey' || + this.dependencies.contextSrv.user.authenticatedBy === 'render') + ) { + return; + } + if (config.showErrorAlert === false) { return; }