dashboard.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. )
  10. func init() {
  11. bus.AddHandler("sql", SaveDashboard)
  12. bus.AddHandler("sql", GetDashboard)
  13. bus.AddHandler("sql", GetDashboards)
  14. bus.AddHandler("sql", DeleteDashboard)
  15. bus.AddHandler("sql", SearchDashboards)
  16. bus.AddHandler("sql", GetDashboardTags)
  17. bus.AddHandler("sql", GetDashboardSlugById)
  18. bus.AddHandler("sql", GetDashboardsByPluginId)
  19. bus.AddHandler("sql", GetFoldersForSignedInUser)
  20. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  21. }
  22. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  23. return inTransaction(func(sess *DBSession) error {
  24. dash := cmd.GetDashboardModel()
  25. // try get existing dashboard
  26. var existing, sameTitle m.Dashboard
  27. if dash.Id > 0 {
  28. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  29. if err != nil {
  30. return err
  31. }
  32. if !dashWithIdExists {
  33. return m.ErrDashboardNotFound
  34. }
  35. // check for is someone else has written in between
  36. if dash.Version != existing.Version {
  37. if cmd.Overwrite {
  38. dash.Version = existing.Version
  39. } else {
  40. return m.ErrDashboardVersionMismatch
  41. }
  42. }
  43. // do not allow plugin dashboard updates without overwrite flag
  44. if existing.PluginId != "" && cmd.Overwrite == false {
  45. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  46. }
  47. }
  48. sameTitleExists, err := sess.Where("org_id=? AND slug=?", dash.OrgId, dash.Slug).Get(&sameTitle)
  49. if err != nil {
  50. return err
  51. }
  52. if sameTitleExists {
  53. // another dashboard with same name
  54. if dash.Id != sameTitle.Id {
  55. if cmd.Overwrite {
  56. dash.Id = sameTitle.Id
  57. dash.Version = sameTitle.Version
  58. } else {
  59. return m.ErrDashboardWithSameNameExists
  60. }
  61. }
  62. }
  63. err = setHasAcl(sess, dash)
  64. if err != nil {
  65. return err
  66. }
  67. parentVersion := dash.Version
  68. affectedRows := int64(0)
  69. if dash.Id == 0 {
  70. dash.Version = 1
  71. metrics.M_Api_Dashboard_Insert.Inc()
  72. dash.Data.Set("version", dash.Version)
  73. affectedRows, err = sess.Insert(dash)
  74. } else {
  75. dash.Version++
  76. dash.Data.Set("version", dash.Version)
  77. if !cmd.UpdatedAt.IsZero() {
  78. dash.Updated = cmd.UpdatedAt
  79. }
  80. affectedRows, err = sess.MustCols("folder_id", "has_acl").Id(dash.Id).Update(dash)
  81. }
  82. if err != nil {
  83. return err
  84. }
  85. if affectedRows == 0 {
  86. return m.ErrDashboardNotFound
  87. }
  88. dashVersion := &m.DashboardVersion{
  89. DashboardId: dash.Id,
  90. ParentVersion: parentVersion,
  91. RestoredFrom: cmd.RestoredFrom,
  92. Version: dash.Version,
  93. Created: time.Now(),
  94. CreatedBy: dash.UpdatedBy,
  95. Message: cmd.Message,
  96. Data: dash.Data,
  97. }
  98. // insert version entry
  99. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  100. return err
  101. } else if affectedRows == 0 {
  102. return m.ErrDashboardNotFound
  103. }
  104. // delete existing tags
  105. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  106. if err != nil {
  107. return err
  108. }
  109. // insert new tags
  110. tags := dash.GetTags()
  111. if len(tags) > 0 {
  112. for _, tag := range tags {
  113. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  114. return err
  115. }
  116. }
  117. }
  118. cmd.Result = dash
  119. return err
  120. })
  121. }
  122. func setHasAcl(sess *DBSession, dash *m.Dashboard) error {
  123. // check if parent has acl
  124. if dash.FolderId > 0 {
  125. var parent m.Dashboard
  126. if hasParent, err := sess.Where("folder_id=?", dash.FolderId).Get(&parent); err != nil {
  127. return err
  128. } else if hasParent && parent.HasAcl {
  129. dash.HasAcl = true
  130. }
  131. }
  132. // check if dash has its own acl
  133. if dash.Id > 0 {
  134. if res, err := sess.Query("SELECT 1 from dashboard_acl WHERE dashboard_id =?", dash.Id); err != nil {
  135. return err
  136. } else {
  137. if len(res) > 0 {
  138. dash.HasAcl = true
  139. }
  140. }
  141. }
  142. return nil
  143. }
  144. func GetDashboard(query *m.GetDashboardQuery) error {
  145. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id}
  146. has, err := x.Get(&dashboard)
  147. if err != nil {
  148. return err
  149. } else if has == false {
  150. return m.ErrDashboardNotFound
  151. }
  152. dashboard.Data.Set("id", dashboard.Id)
  153. query.Result = &dashboard
  154. return nil
  155. }
  156. type DashboardSearchProjection struct {
  157. Id int64
  158. Title string
  159. Slug string
  160. Term string
  161. IsFolder bool
  162. FolderId int64
  163. FolderSlug string
  164. FolderTitle string
  165. }
  166. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  167. limit := query.Limit
  168. if limit == 0 {
  169. limit = 1000
  170. }
  171. sb := NewSearchBuilder(query.SignedInUser, limit).
  172. WithTags(query.Tags).
  173. WithDashboardIdsIn(query.DashboardIds)
  174. if query.IsStarred {
  175. sb.IsStarred()
  176. }
  177. if len(query.Title) > 0 {
  178. sb.WithTitle(query.Title)
  179. }
  180. if len(query.Type) > 0 {
  181. sb.WithType(query.Type)
  182. }
  183. if len(query.FolderIds) > 0 {
  184. sb.WithFolderIds(query.FolderIds)
  185. }
  186. var res []DashboardSearchProjection
  187. sql, params := sb.ToSql()
  188. err := x.Sql(sql, params...).Find(&res)
  189. if err != nil {
  190. return nil, err
  191. }
  192. return res, nil
  193. }
  194. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  195. res, err := findDashboards(query)
  196. if err != nil {
  197. return err
  198. }
  199. makeQueryResult(query, res)
  200. return nil
  201. }
  202. func getHitType(item DashboardSearchProjection) search.HitType {
  203. var hitType search.HitType
  204. if item.IsFolder {
  205. hitType = search.DashHitFolder
  206. } else {
  207. hitType = search.DashHitDB
  208. }
  209. return hitType
  210. }
  211. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  212. query.Result = make([]*search.Hit, 0)
  213. hits := make(map[int64]*search.Hit)
  214. for _, item := range res {
  215. hit, exists := hits[item.Id]
  216. if !exists {
  217. hit = &search.Hit{
  218. Id: item.Id,
  219. Title: item.Title,
  220. Uri: "db/" + item.Slug,
  221. Slug: item.Slug,
  222. Type: getHitType(item),
  223. FolderId: item.FolderId,
  224. FolderTitle: item.FolderTitle,
  225. FolderSlug: item.FolderSlug,
  226. Tags: []string{},
  227. }
  228. query.Result = append(query.Result, hit)
  229. hits[item.Id] = hit
  230. }
  231. if len(item.Term) > 0 {
  232. hit.Tags = append(hit.Tags, item.Term)
  233. }
  234. }
  235. }
  236. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  237. sql := `SELECT
  238. COUNT(*) as count,
  239. term
  240. FROM dashboard
  241. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  242. WHERE dashboard.org_id=?
  243. GROUP BY term`
  244. query.Result = make([]*m.DashboardTagCloudItem, 0)
  245. sess := x.Sql(sql, query.OrgId)
  246. err := sess.Find(&query.Result)
  247. return err
  248. }
  249. func GetFoldersForSignedInUser(query *m.GetFoldersForSignedInUserQuery) error {
  250. query.Result = make([]*m.DashboardFolder, 0)
  251. var err error
  252. if query.SignedInUser.OrgRole == m.ROLE_ADMIN {
  253. sql := `SELECT distinct d.id, d.title
  254. FROM dashboard AS d WHERE d.is_folder = ?
  255. ORDER BY d.title ASC`
  256. err = x.Sql(sql, dialect.BooleanStr(true)).Find(&query.Result)
  257. } else {
  258. params := make([]interface{}, 0)
  259. sql := `SELECT distinct d.id, d.title
  260. FROM dashboard AS d
  261. LEFT JOIN dashboard_acl AS da ON d.id = da.dashboard_id
  262. LEFT JOIN team_member AS ugm ON ugm.team_id = da.team_id
  263. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  264. LEFT JOIN org_user ouRole ON ouRole.role = 'Editor' AND ouRole.user_id = ? AND ouRole.org_id = ?`
  265. params = append(params, query.SignedInUser.UserId)
  266. params = append(params, query.SignedInUser.UserId)
  267. params = append(params, query.OrgId)
  268. sql += ` WHERE
  269. d.org_id = ? AND
  270. d.is_folder = ? AND
  271. (
  272. (d.has_acl = ? AND da.permission > 1 AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  273. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  274. )`
  275. params = append(params, query.OrgId)
  276. params = append(params, dialect.BooleanStr(true))
  277. params = append(params, dialect.BooleanStr(true))
  278. params = append(params, query.SignedInUser.UserId)
  279. params = append(params, query.SignedInUser.UserId)
  280. params = append(params, dialect.BooleanStr(false))
  281. if len(query.Title) > 0 {
  282. sql += " AND d.title " + dialect.LikeStr() + " ?"
  283. params = append(params, "%"+query.Title+"%")
  284. }
  285. sql += ` ORDER BY d.title ASC`
  286. err = x.Sql(sql, params...).Find(&query.Result)
  287. }
  288. return err
  289. }
  290. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  291. return inTransaction(func(sess *DBSession) error {
  292. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  293. has, err := sess.Get(&dashboard)
  294. if err != nil {
  295. return err
  296. } else if has == false {
  297. return m.ErrDashboardNotFound
  298. }
  299. deletes := []string{
  300. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  301. "DELETE FROM star WHERE dashboard_id = ? ",
  302. "DELETE FROM dashboard WHERE id = ?",
  303. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  304. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  305. "DELETE FROM dashboard WHERE folder_id = ?",
  306. "DELETE FROM annotation WHERE dashboard_id = ?",
  307. }
  308. for _, sql := range deletes {
  309. _, err := sess.Exec(sql, dashboard.Id)
  310. if err != nil {
  311. return err
  312. }
  313. }
  314. if err := DeleteAlertDefinition(dashboard.Id, sess); err != nil {
  315. return nil
  316. }
  317. return nil
  318. })
  319. }
  320. func GetDashboards(query *m.GetDashboardsQuery) error {
  321. if len(query.DashboardIds) == 0 {
  322. return m.ErrCommandValidationFailed
  323. }
  324. var dashboards = make([]*m.Dashboard, 0)
  325. err := x.In("id", query.DashboardIds).Find(&dashboards)
  326. query.Result = dashboards
  327. if err != nil {
  328. return err
  329. }
  330. return nil
  331. }
  332. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  333. // The function takes in a list of dashboard ids and the user id and role
  334. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  335. if len(query.DashboardIds) == 0 {
  336. return m.ErrCommandValidationFailed
  337. }
  338. if query.OrgRole == m.ROLE_ADMIN {
  339. var permissions = make([]*m.DashboardPermissionForUser, 0)
  340. for _, d := range query.DashboardIds {
  341. permissions = append(permissions, &m.DashboardPermissionForUser{
  342. DashboardId: d,
  343. Permission: m.PERMISSION_ADMIN,
  344. PermissionName: m.PERMISSION_ADMIN.String(),
  345. })
  346. }
  347. query.Result = permissions
  348. return nil
  349. }
  350. params := make([]interface{}, 0)
  351. // check dashboards that have ACLs via user id, team id or role
  352. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  353. FROM dashboard AS d
  354. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  355. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  356. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  357. `
  358. params = append(params, query.UserId)
  359. //check the user's role for dashboards that do not have hasAcl set
  360. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  361. params = append(params, query.UserId)
  362. params = append(params, query.OrgId)
  363. sql += `
  364. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  365. UNION SELECT 2 AS permission, 'Editor' AS role
  366. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  367. WHERE
  368. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  369. for _, id := range query.DashboardIds {
  370. params = append(params, id)
  371. }
  372. sql += ` AND
  373. d.org_id = ? AND
  374. (
  375. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  376. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  377. )
  378. group by d.id
  379. order by d.id asc`
  380. params = append(params, query.OrgId)
  381. params = append(params, dialect.BooleanStr(true))
  382. params = append(params, query.UserId)
  383. params = append(params, query.UserId)
  384. params = append(params, dialect.BooleanStr(false))
  385. x.ShowSQL(true)
  386. err := x.Sql(sql, params...).Find(&query.Result)
  387. x.ShowSQL(false)
  388. for _, p := range query.Result {
  389. p.PermissionName = p.Permission.String()
  390. }
  391. return err
  392. }
  393. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  394. var dashboards = make([]*m.Dashboard, 0)
  395. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  396. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  397. query.Result = dashboards
  398. if err != nil {
  399. return err
  400. }
  401. return nil
  402. }
  403. type DashboardSlugDTO struct {
  404. Slug string
  405. }
  406. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  407. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  408. var slug = DashboardSlugDTO{}
  409. exists, err := x.Sql(rawSql, query.Id).Get(&slug)
  410. if err != nil {
  411. return err
  412. } else if exists == false {
  413. return m.ErrDashboardNotFound
  414. }
  415. query.Result = slug.Slug
  416. return nil
  417. }