dashboard.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetFoldersForSignedInUser)
  22. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  23. }
  24. var generateNewUid func() string = util.GenerateShortUid
  25. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  26. return inTransaction(func(sess *DBSession) error {
  27. dash := cmd.GetDashboardModel()
  28. // try get existing dashboard
  29. var existing m.Dashboard
  30. if dash.Id != 0 {
  31. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  32. if err != nil {
  33. return err
  34. }
  35. if !dashWithIdExists {
  36. return m.ErrDashboardNotFound
  37. }
  38. // check for is someone else has written in between
  39. if dash.Version != existing.Version {
  40. if cmd.Overwrite {
  41. dash.Version = existing.Version
  42. } else {
  43. return m.ErrDashboardVersionMismatch
  44. }
  45. }
  46. // do not allow plugin dashboard updates without overwrite flag
  47. if existing.PluginId != "" && cmd.Overwrite == false {
  48. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  49. }
  50. } else if dash.Uid != "" {
  51. var sameUid m.Dashboard
  52. sameUidExists, err := sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&sameUid)
  53. if err != nil {
  54. return err
  55. }
  56. if sameUidExists {
  57. // another dashboard with same uid
  58. if dash.Id != sameUid.Id {
  59. if cmd.Overwrite {
  60. dash.Id = sameUid.Id
  61. dash.Version = sameUid.Version
  62. } else {
  63. return m.ErrDashboardWithSameUIDExists
  64. }
  65. }
  66. }
  67. }
  68. if dash.Uid == "" {
  69. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  70. if err != nil {
  71. return err
  72. }
  73. dash.Uid = uid
  74. dash.Data.Set("uid", uid)
  75. }
  76. err := guaranteeDashboardNameIsUniqueInFolder(sess, dash)
  77. if err != nil {
  78. return err
  79. }
  80. err = setHasAcl(sess, dash)
  81. if err != nil {
  82. return err
  83. }
  84. parentVersion := dash.Version
  85. affectedRows := int64(0)
  86. if dash.Id == 0 {
  87. dash.Version = 1
  88. metrics.M_Api_Dashboard_Insert.Inc()
  89. dash.Data.Set("version", dash.Version)
  90. affectedRows, err = sess.Insert(dash)
  91. } else {
  92. dash.Version++
  93. dash.Data.Set("version", dash.Version)
  94. if !cmd.UpdatedAt.IsZero() {
  95. dash.Updated = cmd.UpdatedAt
  96. }
  97. affectedRows, err = sess.MustCols("folder_id", "has_acl").ID(dash.Id).Update(dash)
  98. }
  99. if err != nil {
  100. return err
  101. }
  102. if affectedRows == 0 {
  103. return m.ErrDashboardNotFound
  104. }
  105. dashVersion := &m.DashboardVersion{
  106. DashboardId: dash.Id,
  107. ParentVersion: parentVersion,
  108. RestoredFrom: cmd.RestoredFrom,
  109. Version: dash.Version,
  110. Created: time.Now(),
  111. CreatedBy: dash.UpdatedBy,
  112. Message: cmd.Message,
  113. Data: dash.Data,
  114. }
  115. // insert version entry
  116. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  117. return err
  118. } else if affectedRows == 0 {
  119. return m.ErrDashboardNotFound
  120. }
  121. // delete existing tags
  122. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  123. if err != nil {
  124. return err
  125. }
  126. // insert new tags
  127. tags := dash.GetTags()
  128. if len(tags) > 0 {
  129. for _, tag := range tags {
  130. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  131. return err
  132. }
  133. }
  134. }
  135. cmd.Result = dash
  136. return err
  137. })
  138. }
  139. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  140. for i := 0; i < 3; i++ {
  141. uid := generateNewUid()
  142. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&m.Dashboard{})
  143. if err != nil {
  144. return "", err
  145. }
  146. if !exists {
  147. return uid, nil
  148. }
  149. }
  150. return "", m.ErrDashboardFailedGenerateUniqueUid
  151. }
  152. func guaranteeDashboardNameIsUniqueInFolder(sess *DBSession, dash *m.Dashboard) error {
  153. var sameNameInFolder m.Dashboard
  154. sameNameInFolderExist, err := sess.Where("org_id=? AND title=? AND folder_id = ? AND uid <> ?",
  155. dash.OrgId, dash.Title, dash.FolderId, dash.Uid).
  156. Get(&sameNameInFolder)
  157. if err != nil {
  158. return err
  159. }
  160. if sameNameInFolderExist {
  161. return m.ErrDashboardWithSameNameInFolderExists
  162. }
  163. return nil
  164. }
  165. func setHasAcl(sess *DBSession, dash *m.Dashboard) error {
  166. // check if parent has acl
  167. if dash.FolderId > 0 {
  168. var parent m.Dashboard
  169. if hasParent, err := sess.Where("folder_id=?", dash.FolderId).Get(&parent); err != nil {
  170. return err
  171. } else if hasParent && parent.HasAcl {
  172. dash.HasAcl = true
  173. }
  174. }
  175. // check if dash has its own acl
  176. if dash.Id > 0 {
  177. if res, err := sess.Query("SELECT 1 from dashboard_acl WHERE dashboard_id =?", dash.Id); err != nil {
  178. return err
  179. } else {
  180. if len(res) > 0 {
  181. dash.HasAcl = true
  182. }
  183. }
  184. }
  185. return nil
  186. }
  187. func GetDashboard(query *m.GetDashboardQuery) error {
  188. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  189. has, err := x.Get(&dashboard)
  190. if err != nil {
  191. return err
  192. } else if has == false {
  193. return m.ErrDashboardNotFound
  194. }
  195. dashboard.Data.Set("id", dashboard.Id)
  196. dashboard.Data.Set("uid", dashboard.Uid)
  197. query.Result = &dashboard
  198. return nil
  199. }
  200. type DashboardSearchProjection struct {
  201. Id int64
  202. Uid string
  203. Title string
  204. Slug string
  205. Term string
  206. IsFolder bool
  207. FolderId int64
  208. FolderSlug string
  209. FolderTitle string
  210. }
  211. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  212. limit := query.Limit
  213. if limit == 0 {
  214. limit = 1000
  215. }
  216. sb := NewSearchBuilder(query.SignedInUser, limit).
  217. WithTags(query.Tags).
  218. WithDashboardIdsIn(query.DashboardIds)
  219. if query.IsStarred {
  220. sb.IsStarred()
  221. }
  222. if len(query.Title) > 0 {
  223. sb.WithTitle(query.Title)
  224. }
  225. if len(query.Type) > 0 {
  226. sb.WithType(query.Type)
  227. }
  228. if len(query.FolderIds) > 0 {
  229. sb.WithFolderIds(query.FolderIds)
  230. }
  231. var res []DashboardSearchProjection
  232. sql, params := sb.ToSql()
  233. err := x.Sql(sql, params...).Find(&res)
  234. if err != nil {
  235. return nil, err
  236. }
  237. return res, nil
  238. }
  239. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  240. res, err := findDashboards(query)
  241. if err != nil {
  242. return err
  243. }
  244. makeQueryResult(query, res)
  245. return nil
  246. }
  247. func getHitType(item DashboardSearchProjection) search.HitType {
  248. var hitType search.HitType
  249. if item.IsFolder {
  250. hitType = search.DashHitFolder
  251. } else {
  252. hitType = search.DashHitDB
  253. }
  254. return hitType
  255. }
  256. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  257. query.Result = make([]*search.Hit, 0)
  258. hits := make(map[int64]*search.Hit)
  259. for _, item := range res {
  260. hit, exists := hits[item.Id]
  261. if !exists {
  262. hit = &search.Hit{
  263. Id: item.Id,
  264. Uid: item.Uid,
  265. Title: item.Title,
  266. Uri: "db/" + item.Slug,
  267. Url: m.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  268. Type: getHitType(item),
  269. FolderId: item.FolderId,
  270. FolderTitle: item.FolderTitle,
  271. FolderSlug: item.FolderSlug,
  272. Tags: []string{},
  273. }
  274. query.Result = append(query.Result, hit)
  275. hits[item.Id] = hit
  276. }
  277. if len(item.Term) > 0 {
  278. hit.Tags = append(hit.Tags, item.Term)
  279. }
  280. }
  281. }
  282. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  283. sql := `SELECT
  284. COUNT(*) as count,
  285. term
  286. FROM dashboard
  287. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  288. WHERE dashboard.org_id=?
  289. GROUP BY term`
  290. query.Result = make([]*m.DashboardTagCloudItem, 0)
  291. sess := x.Sql(sql, query.OrgId)
  292. err := sess.Find(&query.Result)
  293. return err
  294. }
  295. func GetFoldersForSignedInUser(query *m.GetFoldersForSignedInUserQuery) error {
  296. query.Result = make([]*m.DashboardFolder, 0)
  297. var err error
  298. if query.SignedInUser.OrgRole == m.ROLE_ADMIN {
  299. sql := `SELECT distinct d.id, d.title
  300. FROM dashboard AS d WHERE d.is_folder = ?
  301. ORDER BY d.title ASC`
  302. err = x.Sql(sql, dialect.BooleanStr(true)).Find(&query.Result)
  303. } else {
  304. params := make([]interface{}, 0)
  305. sql := `SELECT distinct d.id, d.title
  306. FROM dashboard AS d
  307. LEFT JOIN dashboard_acl AS da ON d.id = da.dashboard_id
  308. LEFT JOIN team_member AS ugm ON ugm.team_id = da.team_id
  309. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  310. LEFT JOIN org_user ouRole ON ouRole.role = 'Editor' AND ouRole.user_id = ? AND ouRole.org_id = ?`
  311. params = append(params, query.SignedInUser.UserId)
  312. params = append(params, query.SignedInUser.UserId)
  313. params = append(params, query.OrgId)
  314. sql += `WHERE
  315. d.org_id = ? AND
  316. d.is_folder = 1 AND
  317. (
  318. (d.has_acl = 1 AND da.permission > 1 AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  319. OR (d.has_acl = 0 AND ouRole.id IS NOT NULL)
  320. )`
  321. params = append(params, query.OrgId)
  322. params = append(params, query.SignedInUser.UserId)
  323. params = append(params, query.SignedInUser.UserId)
  324. if len(query.Title) > 0 {
  325. sql += " AND d.title " + dialect.LikeStr() + " ?"
  326. params = append(params, "%"+query.Title+"%")
  327. }
  328. sql += ` ORDER BY d.title ASC`
  329. err = x.Sql(sql, params...).Find(&query.Result)
  330. }
  331. return err
  332. }
  333. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  334. return inTransaction(func(sess *DBSession) error {
  335. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  336. has, err := sess.Get(&dashboard)
  337. if err != nil {
  338. return err
  339. } else if has == false {
  340. return m.ErrDashboardNotFound
  341. }
  342. deletes := []string{
  343. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  344. "DELETE FROM star WHERE dashboard_id = ? ",
  345. "DELETE FROM dashboard WHERE id = ?",
  346. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  347. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  348. "DELETE FROM dashboard WHERE folder_id = ?",
  349. "DELETE FROM annotation WHERE dashboard_id = ?",
  350. }
  351. for _, sql := range deletes {
  352. _, err := sess.Exec(sql, dashboard.Id)
  353. if err != nil {
  354. return err
  355. }
  356. }
  357. if err := DeleteAlertDefinition(dashboard.Id, sess); err != nil {
  358. return nil
  359. }
  360. return nil
  361. })
  362. }
  363. func GetDashboards(query *m.GetDashboardsQuery) error {
  364. if len(query.DashboardIds) == 0 {
  365. return m.ErrCommandValidationFailed
  366. }
  367. var dashboards = make([]*m.Dashboard, 0)
  368. err := x.In("id", query.DashboardIds).Find(&dashboards)
  369. query.Result = dashboards
  370. if err != nil {
  371. return err
  372. }
  373. return nil
  374. }
  375. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  376. // The function takes in a list of dashboard ids and the user id and role
  377. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  378. if len(query.DashboardIds) == 0 {
  379. return m.ErrCommandValidationFailed
  380. }
  381. if query.OrgRole == m.ROLE_ADMIN {
  382. var permissions = make([]*m.DashboardPermissionForUser, 0)
  383. for _, d := range query.DashboardIds {
  384. permissions = append(permissions, &m.DashboardPermissionForUser{
  385. DashboardId: d,
  386. Permission: m.PERMISSION_ADMIN,
  387. PermissionName: m.PERMISSION_ADMIN.String(),
  388. })
  389. }
  390. query.Result = permissions
  391. return nil
  392. }
  393. params := make([]interface{}, 0)
  394. // check dashboards that have ACLs via user id, team id or role
  395. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  396. FROM dashboard AS d
  397. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  398. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  399. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  400. `
  401. params = append(params, query.UserId)
  402. //check the user's role for dashboards that do not have hasAcl set
  403. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  404. params = append(params, query.UserId)
  405. params = append(params, query.OrgId)
  406. sql += `
  407. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS 'role'
  408. UNION SELECT 2 AS permission, 'Editor' AS 'role'
  409. UNION SELECT 4 AS permission, 'Admin' AS 'role') pt ON ouRole.role = pt.role
  410. WHERE
  411. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  412. for _, id := range query.DashboardIds {
  413. params = append(params, id)
  414. }
  415. sql += ` AND
  416. d.org_id = ? AND
  417. (
  418. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  419. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  420. )
  421. group by d.id
  422. order by d.id asc`
  423. params = append(params, dialect.BooleanStr(true))
  424. params = append(params, query.OrgId)
  425. params = append(params, query.UserId)
  426. params = append(params, query.UserId)
  427. params = append(params, dialect.BooleanStr(false))
  428. err := x.Sql(sql, params...).Find(&query.Result)
  429. for _, p := range query.Result {
  430. p.PermissionName = p.Permission.String()
  431. }
  432. return err
  433. }
  434. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  435. var dashboards = make([]*m.Dashboard, 0)
  436. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  437. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  438. query.Result = dashboards
  439. if err != nil {
  440. return err
  441. }
  442. return nil
  443. }
  444. type DashboardSlugDTO struct {
  445. Slug string
  446. }
  447. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  448. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  449. var slug = DashboardSlugDTO{}
  450. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  451. if err != nil {
  452. return err
  453. } else if exists == false {
  454. return m.ErrDashboardNotFound
  455. }
  456. query.Result = slug.Slug
  457. return nil
  458. }
  459. func GetDashboardsBySlug(query *m.GetDashboardsBySlugQuery) error {
  460. var dashboards = make([]*m.Dashboard, 0)
  461. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  462. return err
  463. }
  464. query.Result = dashboards
  465. return nil
  466. }
  467. func GetDashboardUIDById(query *m.GetDashboardUIDByIdQuery) error {
  468. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  469. us := &m.DashboardRef{}
  470. exists, err := x.SQL(rawSql, query.Id).Get(us)
  471. if err != nil {
  472. return err
  473. } else if exists == false {
  474. return m.ErrDashboardNotFound
  475. }
  476. query.Result = us
  477. return nil
  478. }