dashboard.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetFoldersForSignedInUser)
  22. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  23. bus.AddHandler("sql", GetDashboardsBySlug)
  24. }
  25. var generateNewUid func() string = util.GenerateShortUid
  26. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  27. return inTransaction(func(sess *DBSession) error {
  28. dash := cmd.GetDashboardModel()
  29. // try get existing dashboard
  30. var existing m.Dashboard
  31. if dash.Id != 0 {
  32. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  33. if err != nil {
  34. return err
  35. }
  36. if !dashWithIdExists {
  37. return m.ErrDashboardNotFound
  38. }
  39. // check for is someone else has written in between
  40. if dash.Version != existing.Version {
  41. if cmd.Overwrite {
  42. dash.Version = existing.Version
  43. } else {
  44. return m.ErrDashboardVersionMismatch
  45. }
  46. }
  47. // do not allow plugin dashboard updates without overwrite flag
  48. if existing.PluginId != "" && cmd.Overwrite == false {
  49. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  50. }
  51. dash.Created = existing.Created
  52. dash.CreatedBy = existing.CreatedBy
  53. } else if dash.Uid != "" {
  54. var sameUid m.Dashboard
  55. sameUidExists, err := sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&sameUid)
  56. if err != nil {
  57. return err
  58. }
  59. if sameUidExists {
  60. // another dashboard with same uid
  61. if dash.Id != sameUid.Id {
  62. if cmd.Overwrite {
  63. dash.Id = sameUid.Id
  64. dash.Version = sameUid.Version
  65. } else {
  66. return m.ErrDashboardWithSameUIDExists
  67. }
  68. } else {
  69. dash.Created = sameUid.Created
  70. dash.CreatedBy = sameUid.CreatedBy
  71. }
  72. }
  73. }
  74. if dash.Uid == "" {
  75. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  76. if err != nil {
  77. return err
  78. }
  79. dash.Uid = uid
  80. dash.Data.Set("uid", uid)
  81. }
  82. err := guaranteeDashboardNameIsUniqueInFolder(sess, dash)
  83. if err != nil {
  84. return err
  85. }
  86. err = setHasAcl(sess, dash)
  87. if err != nil {
  88. return err
  89. }
  90. parentVersion := dash.Version
  91. affectedRows := int64(0)
  92. if dash.Id == 0 {
  93. dash.Version = 1
  94. metrics.M_Api_Dashboard_Insert.Inc()
  95. dash.Data.Set("version", dash.Version)
  96. affectedRows, err = sess.Insert(dash)
  97. } else {
  98. dash.Version++
  99. dash.Data.Set("version", dash.Version)
  100. if !cmd.UpdatedAt.IsZero() {
  101. dash.Updated = cmd.UpdatedAt
  102. }
  103. affectedRows, err = sess.MustCols("folder_id", "has_acl").ID(dash.Id).Update(dash)
  104. }
  105. if err != nil {
  106. return err
  107. }
  108. if affectedRows == 0 {
  109. return m.ErrDashboardNotFound
  110. }
  111. dashVersion := &m.DashboardVersion{
  112. DashboardId: dash.Id,
  113. ParentVersion: parentVersion,
  114. RestoredFrom: cmd.RestoredFrom,
  115. Version: dash.Version,
  116. Created: time.Now(),
  117. CreatedBy: dash.UpdatedBy,
  118. Message: cmd.Message,
  119. Data: dash.Data,
  120. }
  121. // insert version entry
  122. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  123. return err
  124. } else if affectedRows == 0 {
  125. return m.ErrDashboardNotFound
  126. }
  127. // delete existing tags
  128. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  129. if err != nil {
  130. return err
  131. }
  132. // insert new tags
  133. tags := dash.GetTags()
  134. if len(tags) > 0 {
  135. for _, tag := range tags {
  136. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  137. return err
  138. }
  139. }
  140. }
  141. cmd.Result = dash
  142. return err
  143. })
  144. }
  145. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  146. for i := 0; i < 3; i++ {
  147. uid := generateNewUid()
  148. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&m.Dashboard{})
  149. if err != nil {
  150. return "", err
  151. }
  152. if !exists {
  153. return uid, nil
  154. }
  155. }
  156. return "", m.ErrDashboardFailedGenerateUniqueUid
  157. }
  158. func guaranteeDashboardNameIsUniqueInFolder(sess *DBSession, dash *m.Dashboard) error {
  159. var sameNameInFolder m.Dashboard
  160. sameNameInFolderExist, err := sess.Where("org_id=? AND title=? AND folder_id = ? AND uid <> ?",
  161. dash.OrgId, dash.Title, dash.FolderId, dash.Uid).
  162. Get(&sameNameInFolder)
  163. if err != nil {
  164. return err
  165. }
  166. if sameNameInFolderExist {
  167. return m.ErrDashboardWithSameNameInFolderExists
  168. }
  169. return nil
  170. }
  171. func setHasAcl(sess *DBSession, dash *m.Dashboard) error {
  172. // check if parent has acl
  173. if dash.FolderId > 0 {
  174. var parent m.Dashboard
  175. if hasParent, err := sess.Where("folder_id=?", dash.FolderId).Get(&parent); err != nil {
  176. return err
  177. } else if hasParent && parent.HasAcl {
  178. dash.HasAcl = true
  179. }
  180. }
  181. // check if dash has its own acl
  182. if dash.Id > 0 {
  183. if res, err := sess.Query("SELECT 1 from dashboard_acl WHERE dashboard_id =?", dash.Id); err != nil {
  184. return err
  185. } else {
  186. if len(res) > 0 {
  187. dash.HasAcl = true
  188. }
  189. }
  190. }
  191. return nil
  192. }
  193. func GetDashboard(query *m.GetDashboardQuery) error {
  194. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  195. has, err := x.Get(&dashboard)
  196. if err != nil {
  197. return err
  198. } else if has == false {
  199. return m.ErrDashboardNotFound
  200. }
  201. dashboard.Data.Set("id", dashboard.Id)
  202. dashboard.Data.Set("uid", dashboard.Uid)
  203. query.Result = &dashboard
  204. return nil
  205. }
  206. type DashboardSearchProjection struct {
  207. Id int64
  208. Uid string
  209. Title string
  210. Slug string
  211. Term string
  212. IsFolder bool
  213. FolderId int64
  214. FolderSlug string
  215. FolderTitle string
  216. }
  217. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  218. limit := query.Limit
  219. if limit == 0 {
  220. limit = 1000
  221. }
  222. sb := NewSearchBuilder(query.SignedInUser, limit).
  223. WithTags(query.Tags).
  224. WithDashboardIdsIn(query.DashboardIds)
  225. if query.IsStarred {
  226. sb.IsStarred()
  227. }
  228. if len(query.Title) > 0 {
  229. sb.WithTitle(query.Title)
  230. }
  231. if len(query.Type) > 0 {
  232. sb.WithType(query.Type)
  233. }
  234. if len(query.FolderIds) > 0 {
  235. sb.WithFolderIds(query.FolderIds)
  236. }
  237. var res []DashboardSearchProjection
  238. sql, params := sb.ToSql()
  239. err := x.Sql(sql, params...).Find(&res)
  240. if err != nil {
  241. return nil, err
  242. }
  243. return res, nil
  244. }
  245. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  246. res, err := findDashboards(query)
  247. if err != nil {
  248. return err
  249. }
  250. makeQueryResult(query, res)
  251. return nil
  252. }
  253. func getHitType(item DashboardSearchProjection) search.HitType {
  254. var hitType search.HitType
  255. if item.IsFolder {
  256. hitType = search.DashHitFolder
  257. } else {
  258. hitType = search.DashHitDB
  259. }
  260. return hitType
  261. }
  262. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  263. query.Result = make([]*search.Hit, 0)
  264. hits := make(map[int64]*search.Hit)
  265. for _, item := range res {
  266. hit, exists := hits[item.Id]
  267. if !exists {
  268. hit = &search.Hit{
  269. Id: item.Id,
  270. Uid: item.Uid,
  271. Title: item.Title,
  272. Uri: "db/" + item.Slug,
  273. Url: m.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  274. Type: getHitType(item),
  275. FolderId: item.FolderId,
  276. FolderTitle: item.FolderTitle,
  277. FolderSlug: item.FolderSlug,
  278. Tags: []string{},
  279. }
  280. query.Result = append(query.Result, hit)
  281. hits[item.Id] = hit
  282. }
  283. if len(item.Term) > 0 {
  284. hit.Tags = append(hit.Tags, item.Term)
  285. }
  286. }
  287. }
  288. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  289. sql := `SELECT
  290. COUNT(*) as count,
  291. term
  292. FROM dashboard
  293. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  294. WHERE dashboard.org_id=?
  295. GROUP BY term`
  296. query.Result = make([]*m.DashboardTagCloudItem, 0)
  297. sess := x.Sql(sql, query.OrgId)
  298. err := sess.Find(&query.Result)
  299. return err
  300. }
  301. func GetFoldersForSignedInUser(query *m.GetFoldersForSignedInUserQuery) error {
  302. query.Result = make([]*m.DashboardFolder, 0)
  303. var err error
  304. params := make([]interface{}, 0)
  305. if query.SignedInUser.OrgRole == m.ROLE_ADMIN {
  306. sql := `SELECT distinct d.id, d.title
  307. FROM dashboard AS d WHERE d.is_folder = ?`
  308. params = append(params, dialect.BooleanStr(true))
  309. if len(query.Title) > 0 {
  310. sql += " AND d.title " + dialect.LikeStr() + " ?"
  311. params = append(params, "%"+query.Title+"%")
  312. }
  313. sql += ` ORDER BY d.title ASC`
  314. err = x.Sql(sql, params...).Find(&query.Result)
  315. } else {
  316. sql := `SELECT distinct d.id, d.title
  317. FROM dashboard AS d
  318. LEFT JOIN dashboard_acl AS da ON d.id = da.dashboard_id
  319. LEFT JOIN team_member AS ugm ON ugm.team_id = da.team_id
  320. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  321. LEFT JOIN org_user ouRole ON ouRole.role = 'Editor' AND ouRole.user_id = ? AND ouRole.org_id = ?`
  322. params = append(params, query.SignedInUser.UserId)
  323. params = append(params, query.SignedInUser.UserId)
  324. params = append(params, query.OrgId)
  325. sql += ` WHERE
  326. d.org_id = ? AND
  327. d.is_folder = ? AND
  328. (
  329. (d.has_acl = ? AND da.permission > 1 AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  330. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  331. )`
  332. params = append(params, query.OrgId)
  333. params = append(params, dialect.BooleanStr(true))
  334. params = append(params, dialect.BooleanStr(true))
  335. params = append(params, query.SignedInUser.UserId)
  336. params = append(params, query.SignedInUser.UserId)
  337. params = append(params, dialect.BooleanStr(false))
  338. if len(query.Title) > 0 {
  339. sql += " AND d.title " + dialect.LikeStr() + " ?"
  340. params = append(params, "%"+query.Title+"%")
  341. }
  342. sql += ` ORDER BY d.title ASC`
  343. err = x.Sql(sql, params...).Find(&query.Result)
  344. }
  345. return err
  346. }
  347. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  348. return inTransaction(func(sess *DBSession) error {
  349. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  350. has, err := sess.Get(&dashboard)
  351. if err != nil {
  352. return err
  353. } else if has == false {
  354. return m.ErrDashboardNotFound
  355. }
  356. deletes := []string{
  357. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  358. "DELETE FROM star WHERE dashboard_id = ? ",
  359. "DELETE FROM dashboard WHERE id = ?",
  360. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  361. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  362. "DELETE FROM dashboard WHERE folder_id = ?",
  363. "DELETE FROM annotation WHERE dashboard_id = ?",
  364. }
  365. for _, sql := range deletes {
  366. _, err := sess.Exec(sql, dashboard.Id)
  367. if err != nil {
  368. return err
  369. }
  370. }
  371. if err := DeleteAlertDefinition(dashboard.Id, sess); err != nil {
  372. return nil
  373. }
  374. return nil
  375. })
  376. }
  377. func GetDashboards(query *m.GetDashboardsQuery) error {
  378. if len(query.DashboardIds) == 0 {
  379. return m.ErrCommandValidationFailed
  380. }
  381. var dashboards = make([]*m.Dashboard, 0)
  382. err := x.In("id", query.DashboardIds).Find(&dashboards)
  383. query.Result = dashboards
  384. if err != nil {
  385. return err
  386. }
  387. return nil
  388. }
  389. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  390. // The function takes in a list of dashboard ids and the user id and role
  391. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  392. if len(query.DashboardIds) == 0 {
  393. return m.ErrCommandValidationFailed
  394. }
  395. if query.OrgRole == m.ROLE_ADMIN {
  396. var permissions = make([]*m.DashboardPermissionForUser, 0)
  397. for _, d := range query.DashboardIds {
  398. permissions = append(permissions, &m.DashboardPermissionForUser{
  399. DashboardId: d,
  400. Permission: m.PERMISSION_ADMIN,
  401. PermissionName: m.PERMISSION_ADMIN.String(),
  402. })
  403. }
  404. query.Result = permissions
  405. return nil
  406. }
  407. params := make([]interface{}, 0)
  408. // check dashboards that have ACLs via user id, team id or role
  409. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  410. FROM dashboard AS d
  411. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  412. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  413. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  414. `
  415. params = append(params, query.UserId)
  416. //check the user's role for dashboards that do not have hasAcl set
  417. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  418. params = append(params, query.UserId)
  419. params = append(params, query.OrgId)
  420. sql += `
  421. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  422. UNION SELECT 2 AS permission, 'Editor' AS role
  423. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  424. WHERE
  425. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  426. for _, id := range query.DashboardIds {
  427. params = append(params, id)
  428. }
  429. sql += ` AND
  430. d.org_id = ? AND
  431. (
  432. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  433. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  434. )
  435. group by d.id
  436. order by d.id asc`
  437. params = append(params, query.OrgId)
  438. params = append(params, dialect.BooleanStr(true))
  439. params = append(params, query.UserId)
  440. params = append(params, query.UserId)
  441. params = append(params, dialect.BooleanStr(false))
  442. x.ShowSQL(true)
  443. err := x.Sql(sql, params...).Find(&query.Result)
  444. x.ShowSQL(false)
  445. for _, p := range query.Result {
  446. p.PermissionName = p.Permission.String()
  447. }
  448. return err
  449. }
  450. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  451. var dashboards = make([]*m.Dashboard, 0)
  452. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  453. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  454. query.Result = dashboards
  455. if err != nil {
  456. return err
  457. }
  458. return nil
  459. }
  460. type DashboardSlugDTO struct {
  461. Slug string
  462. }
  463. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  464. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  465. var slug = DashboardSlugDTO{}
  466. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  467. if err != nil {
  468. return err
  469. } else if exists == false {
  470. return m.ErrDashboardNotFound
  471. }
  472. query.Result = slug.Slug
  473. return nil
  474. }
  475. func GetDashboardsBySlug(query *m.GetDashboardsBySlugQuery) error {
  476. var dashboards []*m.Dashboard
  477. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  478. return err
  479. }
  480. query.Result = dashboards
  481. return nil
  482. }
  483. func GetDashboardUIDById(query *m.GetDashboardUIDByIdQuery) error {
  484. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  485. us := &m.DashboardRef{}
  486. exists, err := x.SQL(rawSql, query.Id).Get(us)
  487. if err != nil {
  488. return err
  489. } else if exists == false {
  490. return m.ErrDashboardNotFound
  491. }
  492. query.Result = us
  493. return nil
  494. }