dashboard_folder_test.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410
  1. package sqlstore
  2. import (
  3. "testing"
  4. . "github.com/smartystreets/goconvey/convey"
  5. m "github.com/grafana/grafana/pkg/models"
  6. "github.com/grafana/grafana/pkg/services/search"
  7. )
  8. func TestDashboardFolderDataAccess(t *testing.T) {
  9. Convey("Testing DB", t, func() {
  10. InitTestDB(t)
  11. Convey("Given one dashboard folder with two dashboards and one dashboard in the root folder", func() {
  12. folder := insertTestDashboard("1 test dash folder", 1, 0, true, "prod", "webapp")
  13. dashInRoot := insertTestDashboard("test dash 67", 1, 0, false, "prod", "webapp")
  14. childDash := insertTestDashboard("test dash 23", 1, folder.Id, false, "prod", "webapp")
  15. insertTestDashboard("test dash 45", 1, folder.Id, false, "prod")
  16. currentUser := createUser("viewer", "Viewer", false)
  17. Convey("and no acls are set", func() {
  18. Convey("should return all dashboards", func() {
  19. query := &search.FindPersistedDashboardsQuery{
  20. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  21. OrgId: 1,
  22. DashboardIds: []int64{folder.Id, dashInRoot.Id},
  23. }
  24. err := SearchDashboards(query)
  25. So(err, ShouldBeNil)
  26. So(len(query.Result), ShouldEqual, 2)
  27. So(query.Result[0].Id, ShouldEqual, folder.Id)
  28. So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
  29. })
  30. })
  31. Convey("and acl is set for dashboard folder", func() {
  32. var otherUser int64 = 999
  33. testHelperUpdateDashboardAcl(folder.Id, m.DashboardAcl{DashboardId: folder.Id, OrgId: 1, UserId: otherUser, Permission: m.PERMISSION_EDIT})
  34. Convey("should not return folder", func() {
  35. query := &search.FindPersistedDashboardsQuery{
  36. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  37. OrgId: 1, DashboardIds: []int64{folder.Id, dashInRoot.Id},
  38. }
  39. err := SearchDashboards(query)
  40. So(err, ShouldBeNil)
  41. So(len(query.Result), ShouldEqual, 1)
  42. So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
  43. })
  44. Convey("when the user is given permission", func() {
  45. testHelperUpdateDashboardAcl(folder.Id, m.DashboardAcl{DashboardId: folder.Id, OrgId: 1, UserId: currentUser.Id, Permission: m.PERMISSION_EDIT})
  46. Convey("should be able to access folder", func() {
  47. query := &search.FindPersistedDashboardsQuery{
  48. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  49. OrgId: 1,
  50. DashboardIds: []int64{folder.Id, dashInRoot.Id},
  51. }
  52. err := SearchDashboards(query)
  53. So(err, ShouldBeNil)
  54. So(len(query.Result), ShouldEqual, 2)
  55. So(query.Result[0].Id, ShouldEqual, folder.Id)
  56. So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
  57. })
  58. })
  59. Convey("when the user is an admin", func() {
  60. Convey("should be able to access folder", func() {
  61. query := &search.FindPersistedDashboardsQuery{
  62. SignedInUser: &m.SignedInUser{
  63. UserId: currentUser.Id,
  64. OrgId: 1,
  65. OrgRole: m.ROLE_ADMIN,
  66. },
  67. OrgId: 1,
  68. DashboardIds: []int64{folder.Id, dashInRoot.Id},
  69. }
  70. err := SearchDashboards(query)
  71. So(err, ShouldBeNil)
  72. So(len(query.Result), ShouldEqual, 2)
  73. So(query.Result[0].Id, ShouldEqual, folder.Id)
  74. So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
  75. })
  76. })
  77. })
  78. Convey("and acl is set for dashboard child and folder has all permissions removed", func() {
  79. var otherUser int64 = 999
  80. testHelperUpdateDashboardAcl(folder.Id)
  81. testHelperUpdateDashboardAcl(childDash.Id, m.DashboardAcl{DashboardId: folder.Id, OrgId: 1, UserId: otherUser, Permission: m.PERMISSION_EDIT})
  82. Convey("should not return folder or child", func() {
  83. query := &search.FindPersistedDashboardsQuery{SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1, DashboardIds: []int64{folder.Id, childDash.Id, dashInRoot.Id}}
  84. err := SearchDashboards(query)
  85. So(err, ShouldBeNil)
  86. So(len(query.Result), ShouldEqual, 1)
  87. So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
  88. })
  89. Convey("when the user is given permission to child", func() {
  90. testHelperUpdateDashboardAcl(childDash.Id, m.DashboardAcl{DashboardId: childDash.Id, OrgId: 1, UserId: currentUser.Id, Permission: m.PERMISSION_EDIT})
  91. Convey("should be able to search for child dashboard but not folder", func() {
  92. query := &search.FindPersistedDashboardsQuery{SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1, DashboardIds: []int64{folder.Id, childDash.Id, dashInRoot.Id}}
  93. err := SearchDashboards(query)
  94. So(err, ShouldBeNil)
  95. So(len(query.Result), ShouldEqual, 2)
  96. So(query.Result[0].Id, ShouldEqual, childDash.Id)
  97. So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
  98. })
  99. })
  100. Convey("when the user is an admin", func() {
  101. Convey("should be able to search for child dash and folder", func() {
  102. query := &search.FindPersistedDashboardsQuery{
  103. SignedInUser: &m.SignedInUser{
  104. UserId: currentUser.Id,
  105. OrgId: 1,
  106. OrgRole: m.ROLE_ADMIN,
  107. },
  108. OrgId: 1,
  109. DashboardIds: []int64{folder.Id, dashInRoot.Id, childDash.Id},
  110. }
  111. err := SearchDashboards(query)
  112. So(err, ShouldBeNil)
  113. So(len(query.Result), ShouldEqual, 3)
  114. So(query.Result[0].Id, ShouldEqual, folder.Id)
  115. So(query.Result[1].Id, ShouldEqual, childDash.Id)
  116. So(query.Result[2].Id, ShouldEqual, dashInRoot.Id)
  117. })
  118. })
  119. })
  120. })
  121. Convey("Given two dashboard folders with one dashboard each and one dashboard in the root folder", func() {
  122. folder1 := insertTestDashboard("1 test dash folder", 1, 0, true, "prod")
  123. folder2 := insertTestDashboard("2 test dash folder", 1, 0, true, "prod")
  124. dashInRoot := insertTestDashboard("test dash 67", 1, 0, false, "prod")
  125. childDash1 := insertTestDashboard("child dash 1", 1, folder1.Id, false, "prod")
  126. childDash2 := insertTestDashboard("child dash 2", 1, folder2.Id, false, "prod")
  127. currentUser := createUser("viewer", "Viewer", false)
  128. var rootFolderId int64 = 0
  129. Convey("and one folder is expanded, the other collapsed", func() {
  130. Convey("should return dashboards in root and expanded folder", func() {
  131. query := &search.FindPersistedDashboardsQuery{FolderIds: []int64{rootFolderId, folder1.Id}, SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1}
  132. err := SearchDashboards(query)
  133. So(err, ShouldBeNil)
  134. So(len(query.Result), ShouldEqual, 4)
  135. So(query.Result[0].Id, ShouldEqual, folder1.Id)
  136. So(query.Result[1].Id, ShouldEqual, folder2.Id)
  137. So(query.Result[2].Id, ShouldEqual, childDash1.Id)
  138. So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
  139. })
  140. })
  141. Convey("and acl is set for one dashboard folder", func() {
  142. var otherUser int64 = 999
  143. testHelperUpdateDashboardAcl(folder1.Id, m.DashboardAcl{DashboardId: folder1.Id, OrgId: 1, UserId: otherUser, Permission: m.PERMISSION_EDIT})
  144. Convey("and a dashboard is moved from folder without acl to the folder with an acl", func() {
  145. moveDashboard(1, childDash2.Data, folder1.Id)
  146. Convey("should not return folder with acl or its children", func() {
  147. query := &search.FindPersistedDashboardsQuery{
  148. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  149. OrgId: 1,
  150. DashboardIds: []int64{folder1.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
  151. }
  152. err := SearchDashboards(query)
  153. So(err, ShouldBeNil)
  154. So(len(query.Result), ShouldEqual, 1)
  155. So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
  156. })
  157. })
  158. Convey("and a dashboard is moved from folder with acl to the folder without an acl", func() {
  159. moveDashboard(1, childDash1.Data, folder2.Id)
  160. Convey("should return folder without acl and its children", func() {
  161. query := &search.FindPersistedDashboardsQuery{
  162. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  163. OrgId: 1,
  164. DashboardIds: []int64{folder2.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
  165. }
  166. err := SearchDashboards(query)
  167. So(err, ShouldBeNil)
  168. So(len(query.Result), ShouldEqual, 4)
  169. So(query.Result[0].Id, ShouldEqual, folder2.Id)
  170. So(query.Result[1].Id, ShouldEqual, childDash1.Id)
  171. So(query.Result[2].Id, ShouldEqual, childDash2.Id)
  172. So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
  173. })
  174. })
  175. Convey("and a dashboard with an acl is moved to the folder without an acl", func() {
  176. testHelperUpdateDashboardAcl(childDash1.Id, m.DashboardAcl{DashboardId: childDash1.Id, OrgId: 1, UserId: otherUser, Permission: m.PERMISSION_EDIT})
  177. moveDashboard(1, childDash1.Data, folder2.Id)
  178. Convey("should return folder without acl but not the dashboard with acl", func() {
  179. query := &search.FindPersistedDashboardsQuery{
  180. SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  181. OrgId: 1,
  182. DashboardIds: []int64{folder2.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
  183. }
  184. err := SearchDashboards(query)
  185. So(err, ShouldBeNil)
  186. So(len(query.Result), ShouldEqual, 4)
  187. So(query.Result[0].Id, ShouldEqual, folder2.Id)
  188. So(query.Result[1].Id, ShouldEqual, childDash1.Id)
  189. So(query.Result[2].Id, ShouldEqual, childDash2.Id)
  190. So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
  191. })
  192. })
  193. })
  194. })
  195. Convey("Given two dashboard folders", func() {
  196. folder1 := insertTestDashboard("1 test dash folder", 1, 0, true, "prod")
  197. folder2 := insertTestDashboard("2 test dash folder", 1, 0, true, "prod")
  198. insertTestDashboard("folder in another org", 2, 0, true, "prod")
  199. adminUser := createUser("admin", "Admin", true)
  200. editorUser := createUser("editor", "Editor", false)
  201. viewerUser := createUser("viewer", "Viewer", false)
  202. Convey("Admin users", func() {
  203. Convey("Should have write access to all dashboard folders in their org", func() {
  204. query := search.FindPersistedDashboardsQuery{
  205. OrgId: 1,
  206. SignedInUser: &m.SignedInUser{UserId: adminUser.Id, OrgRole: m.ROLE_ADMIN, OrgId: 1},
  207. Permission: m.PERMISSION_VIEW,
  208. Type: "dash-folder",
  209. }
  210. err := SearchDashboards(&query)
  211. So(err, ShouldBeNil)
  212. So(len(query.Result), ShouldEqual, 2)
  213. So(query.Result[0].Id, ShouldEqual, folder1.Id)
  214. So(query.Result[1].Id, ShouldEqual, folder2.Id)
  215. })
  216. Convey("should have write access to all folders and dashboards", func() {
  217. query := m.GetDashboardPermissionsForUserQuery{
  218. DashboardIds: []int64{folder1.Id, folder2.Id},
  219. OrgId: 1,
  220. UserId: adminUser.Id,
  221. OrgRole: m.ROLE_ADMIN,
  222. }
  223. err := GetDashboardPermissionsForUser(&query)
  224. So(err, ShouldBeNil)
  225. So(len(query.Result), ShouldEqual, 2)
  226. So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
  227. So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_ADMIN)
  228. So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
  229. So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_ADMIN)
  230. })
  231. Convey("should have edit permission in folders", func() {
  232. query := &m.HasEditPermissionInFoldersQuery{
  233. SignedInUser: &m.SignedInUser{UserId: adminUser.Id, OrgId: 1, OrgRole: m.ROLE_ADMIN},
  234. }
  235. err := HasEditPermissionInFolders(query)
  236. So(err, ShouldBeNil)
  237. So(query.Result, ShouldBeTrue)
  238. })
  239. })
  240. Convey("Editor users", func() {
  241. query := search.FindPersistedDashboardsQuery{
  242. OrgId: 1,
  243. SignedInUser: &m.SignedInUser{UserId: editorUser.Id, OrgRole: m.ROLE_EDITOR, OrgId: 1},
  244. Permission: m.PERMISSION_EDIT,
  245. }
  246. Convey("Should have write access to all dashboard folders with default ACL", func() {
  247. err := SearchDashboards(&query)
  248. So(err, ShouldBeNil)
  249. So(len(query.Result), ShouldEqual, 2)
  250. So(query.Result[0].Id, ShouldEqual, folder1.Id)
  251. So(query.Result[1].Id, ShouldEqual, folder2.Id)
  252. })
  253. Convey("should have edit access to folders with default ACL", func() {
  254. query := m.GetDashboardPermissionsForUserQuery{
  255. DashboardIds: []int64{folder1.Id, folder2.Id},
  256. OrgId: 1,
  257. UserId: editorUser.Id,
  258. OrgRole: m.ROLE_EDITOR,
  259. }
  260. err := GetDashboardPermissionsForUser(&query)
  261. So(err, ShouldBeNil)
  262. So(len(query.Result), ShouldEqual, 2)
  263. So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
  264. So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_EDIT)
  265. So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
  266. So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_EDIT)
  267. })
  268. Convey("Should have write access to one dashboard folder if default role changed to view for one folder", func() {
  269. testHelperUpdateDashboardAcl(folder1.Id, m.DashboardAcl{DashboardId: folder1.Id, OrgId: 1, UserId: editorUser.Id, Permission: m.PERMISSION_VIEW})
  270. err := SearchDashboards(&query)
  271. So(err, ShouldBeNil)
  272. So(len(query.Result), ShouldEqual, 1)
  273. So(query.Result[0].Id, ShouldEqual, folder2.Id)
  274. })
  275. Convey("should have edit permission in folders", func() {
  276. query := &m.HasEditPermissionInFoldersQuery{
  277. SignedInUser: &m.SignedInUser{UserId: editorUser.Id, OrgId: 1, OrgRole: m.ROLE_EDITOR},
  278. }
  279. err := HasEditPermissionInFolders(query)
  280. So(err, ShouldBeNil)
  281. So(query.Result, ShouldBeTrue)
  282. })
  283. })
  284. Convey("Viewer users", func() {
  285. query := search.FindPersistedDashboardsQuery{
  286. OrgId: 1,
  287. SignedInUser: &m.SignedInUser{UserId: viewerUser.Id, OrgRole: m.ROLE_VIEWER, OrgId: 1},
  288. Permission: m.PERMISSION_EDIT,
  289. }
  290. Convey("Should have no write access to any dashboard folders with default ACL", func() {
  291. err := SearchDashboards(&query)
  292. So(err, ShouldBeNil)
  293. So(len(query.Result), ShouldEqual, 0)
  294. })
  295. Convey("should have view access to folders with default ACL", func() {
  296. query := m.GetDashboardPermissionsForUserQuery{
  297. DashboardIds: []int64{folder1.Id, folder2.Id},
  298. OrgId: 1,
  299. UserId: viewerUser.Id,
  300. OrgRole: m.ROLE_VIEWER,
  301. }
  302. err := GetDashboardPermissionsForUser(&query)
  303. So(err, ShouldBeNil)
  304. So(len(query.Result), ShouldEqual, 2)
  305. So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
  306. So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_VIEW)
  307. So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
  308. So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_VIEW)
  309. })
  310. Convey("Should be able to get one dashboard folder if default role changed to edit for one folder", func() {
  311. testHelperUpdateDashboardAcl(folder1.Id, m.DashboardAcl{DashboardId: folder1.Id, OrgId: 1, UserId: viewerUser.Id, Permission: m.PERMISSION_EDIT})
  312. err := SearchDashboards(&query)
  313. So(err, ShouldBeNil)
  314. So(len(query.Result), ShouldEqual, 1)
  315. So(query.Result[0].Id, ShouldEqual, folder1.Id)
  316. })
  317. Convey("should not have edit permission in folders", func() {
  318. query := &m.HasEditPermissionInFoldersQuery{
  319. SignedInUser: &m.SignedInUser{UserId: viewerUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  320. }
  321. err := HasEditPermissionInFolders(query)
  322. So(err, ShouldBeNil)
  323. So(query.Result, ShouldBeFalse)
  324. })
  325. Convey("and admin permission is given for user with org role viewer in one dashboard folder", func() {
  326. testHelperUpdateDashboardAcl(folder1.Id, m.DashboardAcl{DashboardId: folder1.Id, OrgId: 1, UserId: viewerUser.Id, Permission: m.PERMISSION_ADMIN})
  327. Convey("should have edit permission in folders", func() {
  328. query := &m.HasEditPermissionInFoldersQuery{
  329. SignedInUser: &m.SignedInUser{UserId: viewerUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  330. }
  331. err := HasEditPermissionInFolders(query)
  332. So(err, ShouldBeNil)
  333. So(query.Result, ShouldBeTrue)
  334. })
  335. })
  336. Convey("and edit permission is given for user with org role viewer in one dashboard folder", func() {
  337. testHelperUpdateDashboardAcl(folder1.Id, m.DashboardAcl{DashboardId: folder1.Id, OrgId: 1, UserId: viewerUser.Id, Permission: m.PERMISSION_EDIT})
  338. Convey("should have edit permission in folders", func() {
  339. query := &m.HasEditPermissionInFoldersQuery{
  340. SignedInUser: &m.SignedInUser{UserId: viewerUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
  341. }
  342. err := HasEditPermissionInFolders(query)
  343. So(err, ShouldBeNil)
  344. So(query.Result, ShouldBeTrue)
  345. })
  346. })
  347. })
  348. })
  349. })
  350. }