guardian.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168
  1. package guardian
  2. import (
  3. "github.com/grafana/grafana/pkg/bus"
  4. "github.com/grafana/grafana/pkg/log"
  5. m "github.com/grafana/grafana/pkg/models"
  6. "github.com/grafana/grafana/pkg/setting"
  7. )
  8. type DashboardGuardian struct {
  9. user *m.SignedInUser
  10. dashId int64
  11. orgId int64
  12. acl []*m.DashboardAclInfoDTO
  13. groups []*m.Team
  14. log log.Logger
  15. }
  16. func NewDashboardGuardian(dashId int64, orgId int64, user *m.SignedInUser) *DashboardGuardian {
  17. return &DashboardGuardian{
  18. user: user,
  19. dashId: dashId,
  20. orgId: orgId,
  21. log: log.New("guardians.dashboard"),
  22. }
  23. }
  24. func (g *DashboardGuardian) CanSave() (bool, error) {
  25. return g.HasPermission(m.PERMISSION_EDIT)
  26. }
  27. func (g *DashboardGuardian) CanEdit() (bool, error) {
  28. if setting.ViewersCanEdit {
  29. return g.HasPermission(m.PERMISSION_VIEW)
  30. }
  31. return g.HasPermission(m.PERMISSION_EDIT)
  32. }
  33. func (g *DashboardGuardian) CanView() (bool, error) {
  34. return g.HasPermission(m.PERMISSION_VIEW)
  35. }
  36. func (g *DashboardGuardian) CanAdmin() (bool, error) {
  37. return g.HasPermission(m.PERMISSION_ADMIN)
  38. }
  39. func (g *DashboardGuardian) HasPermission(permission m.PermissionType) (bool, error) {
  40. if g.user.OrgRole == m.ROLE_ADMIN {
  41. return true, nil
  42. }
  43. acl, err := g.GetAcl()
  44. if err != nil {
  45. return false, err
  46. }
  47. return g.checkAcl(permission, acl)
  48. }
  49. func (g *DashboardGuardian) checkAcl(permission m.PermissionType, acl []*m.DashboardAclInfoDTO) (bool, error) {
  50. orgRole := g.user.OrgRole
  51. teamAclItems := []*m.DashboardAclInfoDTO{}
  52. for _, p := range acl {
  53. // user match
  54. if !g.user.IsAnonymous {
  55. if p.UserId == g.user.UserId && p.Permission >= permission {
  56. return true, nil
  57. }
  58. }
  59. // role match
  60. if p.Role != nil {
  61. if *p.Role == orgRole && p.Permission >= permission {
  62. return true, nil
  63. }
  64. }
  65. // remember this rule for later
  66. if p.TeamId > 0 {
  67. teamAclItems = append(teamAclItems, p)
  68. }
  69. }
  70. // do we have group rules?
  71. if len(teamAclItems) == 0 {
  72. return false, nil
  73. }
  74. // load groups
  75. teams, err := g.getTeams()
  76. if err != nil {
  77. return false, err
  78. }
  79. // evalute group rules
  80. for _, p := range acl {
  81. for _, ug := range teams {
  82. if ug.Id == p.TeamId && p.Permission >= permission {
  83. return true, nil
  84. }
  85. }
  86. }
  87. return false, nil
  88. }
  89. func (g *DashboardGuardian) CheckPermissionBeforeRemove(permission m.PermissionType, aclIdToRemove int64) (bool, error) {
  90. if g.user.OrgRole == m.ROLE_ADMIN {
  91. return true, nil
  92. }
  93. acl, err := g.GetAcl()
  94. if err != nil {
  95. return false, err
  96. }
  97. for i, p := range acl {
  98. if p.Id == aclIdToRemove {
  99. acl = append(acl[:i], acl[i+1:]...)
  100. break
  101. }
  102. }
  103. return g.checkAcl(permission, acl)
  104. }
  105. func (g *DashboardGuardian) CheckPermissionBeforeUpdate(permission m.PermissionType, updatePermissions []*m.DashboardAcl) (bool, error) {
  106. if g.user.OrgRole == m.ROLE_ADMIN {
  107. return true, nil
  108. }
  109. acl := []*m.DashboardAclInfoDTO{}
  110. for _, p := range updatePermissions {
  111. acl = append(acl, &m.DashboardAclInfoDTO{UserId: p.UserId, TeamId: p.TeamId, Role: p.Role, Permission: p.Permission})
  112. }
  113. return g.checkAcl(permission, acl)
  114. }
  115. // Returns dashboard acl
  116. func (g *DashboardGuardian) GetAcl() ([]*m.DashboardAclInfoDTO, error) {
  117. if g.acl != nil {
  118. return g.acl, nil
  119. }
  120. query := m.GetDashboardAclInfoListQuery{DashboardId: g.dashId, OrgId: g.orgId}
  121. if err := bus.Dispatch(&query); err != nil {
  122. return nil, err
  123. }
  124. g.acl = query.Result
  125. return g.acl, nil
  126. }
  127. func (g *DashboardGuardian) getTeams() ([]*m.Team, error) {
  128. if g.groups != nil {
  129. return g.groups, nil
  130. }
  131. query := m.GetTeamsByUserQuery{UserId: g.user.UserId}
  132. err := bus.Dispatch(&query)
  133. g.groups = query.Result
  134. return query.Result, err
  135. }