RBAC: Return 404 instead of 403 if a dashboard cannot be found (#102815)

return 404 instead of 403 if a dashboard cannot be found
This commit is contained in:
Ieva
2025-03-26 12:26:14 +00:00
committed by GitHub
parent fe1f5bc72b
commit ff6039567b
8 changed files with 83 additions and 64 deletions
+12
View File
@@ -20,6 +20,7 @@ import (
"github.com/grafana/grafana/pkg/models/usertoken"
"github.com/grafana/grafana/pkg/services/authn"
contextmodel "github.com/grafana/grafana/pkg/services/contexthandler/model"
"github.com/grafana/grafana/pkg/services/dashboards/dashboardaccess"
"github.com/grafana/grafana/pkg/services/org"
"github.com/grafana/grafana/pkg/setting"
"github.com/grafana/grafana/pkg/util"
@@ -87,6 +88,17 @@ func deny(c *contextmodel.ReqContext, evaluator Evaluator, err error) {
id := newID()
if err != nil {
c.Logger.Error("Error from access control system", "error", err, "accessErrorID", id)
// Return 404s for dashboard not found errors, our plugins rely on being able to distinguish between access denied and not found.
var dashboardErr dashboardaccess.DashboardErr
if ok := errors.As(err, &dashboardErr); ok {
if c.IsApiRequest() && dashboardErr.StatusCode == http.StatusNotFound {
c.JSON(http.StatusNotFound, map[string]string{
"title": "Not found", // the component needs to pick this up
"message": dashboardErr.Error(),
})
return
}
}
} else {
c.Logger.Info(
"Access denied",