Zanzana: Fix dashboard access evaluation in folders (#114718)

* Zanzana: Fix dashboard access evaluation in folders

* add negative test

* Fix listing
This commit is contained in:
Alexander Zobnin
2025-12-04 09:36:03 +01:00
committed by GitHub
parent 1ba57a505a
commit f4fbbcc4f4
5 changed files with 86 additions and 0 deletions
@@ -12,6 +12,7 @@ import (
"go.opentelemetry.io/otel/codes"
"google.golang.org/protobuf/types/known/structpb"
dashboardV1 "github.com/grafana/grafana/apps/dashboard/pkg/apis/dashboard/v1beta1"
"github.com/grafana/grafana/pkg/services/authz/zanzana/common"
)
@@ -148,6 +149,18 @@ func (s *Server) checkGeneric(ctx context.Context, subject, relation string, res
folderRelation = common.SubresourceRelation(relation)
)
if isFolderPermissionBasedResource(resource.GroupResource()) {
// Check if resource inherits permissions from the folder (like dashboards in a folder)
res, err := s.openfgaCheck(ctx, store, subject, relation, folderIdent, contextuals, resourceCtx)
if err != nil {
return nil, err
}
if res.GetAllowed() {
return &authzv1.CheckResponse{Allowed: res.GetAllowed()}, nil
}
}
if folderIdent != "" && common.IsSubresourceRelation(folderRelation) {
// Check if subject has access as a sub resource for the folder
res, err := s.openfgaCheck(ctx, store, subject, folderRelation, folderIdent, contextuals, resourceCtx)
@@ -196,3 +209,12 @@ func (s *Server) openfgaCheck(ctx context.Context, store *storeInfo, subject, re
return res, nil
}
var folderPermissionBasedResources = map[string]bool{
// dashboard.grafana.app/dashboards
common.FormatGroupResource(dashboardV1.DashboardResourceInfo.GroupResource().Group, dashboardV1.DashboardResourceInfo.GroupResource().Resource, ""): true,
}
func isFolderPermissionBasedResource(resource string) bool {
return folderPermissionBasedResources[resource]
}