team.go 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385
  1. package sqlstore
  2. import (
  3. "bytes"
  4. "fmt"
  5. "time"
  6. "github.com/grafana/grafana/pkg/bus"
  7. m "github.com/grafana/grafana/pkg/models"
  8. )
  9. func init() {
  10. bus.AddHandler("sql", CreateTeam)
  11. bus.AddHandler("sql", UpdateTeam)
  12. bus.AddHandler("sql", DeleteTeam)
  13. bus.AddHandler("sql", SearchTeams)
  14. bus.AddHandler("sql", GetTeamById)
  15. bus.AddHandler("sql", GetTeamsByUser)
  16. bus.AddHandler("sql", AddTeamMember)
  17. bus.AddHandler("sql", UpdateTeamMember)
  18. bus.AddHandler("sql", RemoveTeamMember)
  19. bus.AddHandler("sql", GetTeamMembers)
  20. }
  21. func getTeamSearchSqlBase() string {
  22. return `SELECT
  23. team.id as id,
  24. team.org_id,
  25. team.name as name,
  26. team.email as email,
  27. (SELECT COUNT(*) from team_member where team_member.team_id = team.id) as member_count,
  28. team_member.permission
  29. FROM team as team
  30. INNER JOIN team_member on team.id = team_member.team_id AND team_member.user_id = ? `
  31. }
  32. func getTeamSelectSqlBase() string {
  33. return `SELECT
  34. team.id as id,
  35. team.org_id,
  36. team.name as name,
  37. team.email as email,
  38. (SELECT COUNT(*) from team_member where team_member.team_id = team.id) as member_count
  39. FROM team as team `
  40. }
  41. func CreateTeam(cmd *m.CreateTeamCommand) error {
  42. return inTransaction(func(sess *DBSession) error {
  43. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, 0, sess); err != nil {
  44. return err
  45. } else if isNameTaken {
  46. return m.ErrTeamNameTaken
  47. }
  48. team := m.Team{
  49. Name: cmd.Name,
  50. Email: cmd.Email,
  51. OrgId: cmd.OrgId,
  52. Created: time.Now(),
  53. Updated: time.Now(),
  54. }
  55. _, err := sess.Insert(&team)
  56. cmd.Result = team
  57. return err
  58. })
  59. }
  60. func UpdateTeam(cmd *m.UpdateTeamCommand) error {
  61. return inTransaction(func(sess *DBSession) error {
  62. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, cmd.Id, sess); err != nil {
  63. return err
  64. } else if isNameTaken {
  65. return m.ErrTeamNameTaken
  66. }
  67. team := m.Team{
  68. Name: cmd.Name,
  69. Email: cmd.Email,
  70. Updated: time.Now(),
  71. }
  72. sess.MustCols("email")
  73. affectedRows, err := sess.ID(cmd.Id).Update(&team)
  74. if err != nil {
  75. return err
  76. }
  77. if affectedRows == 0 {
  78. return m.ErrTeamNotFound
  79. }
  80. return nil
  81. })
  82. }
  83. // DeleteTeam will delete a team, its member and any permissions connected to the team
  84. func DeleteTeam(cmd *m.DeleteTeamCommand) error {
  85. return inTransaction(func(sess *DBSession) error {
  86. if _, err := teamExists(cmd.OrgId, cmd.Id, sess); err != nil {
  87. return err
  88. }
  89. deletes := []string{
  90. "DELETE FROM team_member WHERE org_id=? and team_id = ?",
  91. "DELETE FROM team WHERE org_id=? and id = ?",
  92. "DELETE FROM dashboard_acl WHERE org_id=? and team_id = ?",
  93. }
  94. for _, sql := range deletes {
  95. _, err := sess.Exec(sql, cmd.OrgId, cmd.Id)
  96. if err != nil {
  97. return err
  98. }
  99. }
  100. return nil
  101. })
  102. }
  103. func teamExists(orgId int64, teamId int64, sess *DBSession) (bool, error) {
  104. if res, err := sess.Query("SELECT 1 from team WHERE org_id=? and id=?", orgId, teamId); err != nil {
  105. return false, err
  106. } else if len(res) != 1 {
  107. return false, m.ErrTeamNotFound
  108. }
  109. return true, nil
  110. }
  111. func isTeamNameTaken(orgId int64, name string, existingId int64, sess *DBSession) (bool, error) {
  112. var team m.Team
  113. exists, err := sess.Where("org_id=? and name=?", orgId, name).Get(&team)
  114. if err != nil {
  115. return false, nil
  116. }
  117. if exists && existingId != team.Id {
  118. return true, nil
  119. }
  120. return false, nil
  121. }
  122. func SearchTeams(query *m.SearchTeamsQuery) error {
  123. query.Result = m.SearchTeamQueryResult{
  124. Teams: make([]*m.TeamDTO, 0),
  125. }
  126. queryWithWildcards := "%" + query.Query + "%"
  127. var sql bytes.Buffer
  128. params := make([]interface{}, 0)
  129. if query.UserIdFilter > 0 {
  130. sql.WriteString(getTeamSearchSqlBase())
  131. params = append(params, query.UserIdFilter)
  132. } else {
  133. sql.WriteString(getTeamSelectSqlBase())
  134. }
  135. sql.WriteString(` WHERE team.org_id = ?`)
  136. params = append(params, query.OrgId)
  137. if query.Query != "" {
  138. sql.WriteString(` and team.name ` + dialect.LikeStr() + ` ?`)
  139. params = append(params, queryWithWildcards)
  140. }
  141. if query.Name != "" {
  142. sql.WriteString(` and team.name = ?`)
  143. params = append(params, query.Name)
  144. }
  145. sql.WriteString(` order by team.name asc`)
  146. if query.Limit != 0 {
  147. offset := query.Limit * (query.Page - 1)
  148. sql.WriteString(dialect.LimitOffset(int64(query.Limit), int64(offset)))
  149. }
  150. if err := x.SQL(sql.String(), params...).Find(&query.Result.Teams); err != nil {
  151. return err
  152. }
  153. team := m.Team{}
  154. countSess := x.Table("team")
  155. if query.Query != "" {
  156. countSess.Where(`name `+dialect.LikeStr()+` ?`, queryWithWildcards)
  157. }
  158. if query.Name != "" {
  159. countSess.Where("name=?", query.Name)
  160. }
  161. count, err := countSess.Count(&team)
  162. query.Result.TotalCount = count
  163. return err
  164. }
  165. func GetTeamById(query *m.GetTeamByIdQuery) error {
  166. var sql bytes.Buffer
  167. sql.WriteString(getTeamSelectSqlBase())
  168. sql.WriteString(` WHERE team.org_id = ? and team.id = ?`)
  169. var team m.TeamDTO
  170. exists, err := x.SQL(sql.String(), query.OrgId, query.Id).Get(&team)
  171. if err != nil {
  172. return err
  173. }
  174. if !exists {
  175. return m.ErrTeamNotFound
  176. }
  177. query.Result = &team
  178. return nil
  179. }
  180. // GetTeamsByUser is used by the Guardian when checking a users' permissions
  181. func GetTeamsByUser(query *m.GetTeamsByUserQuery) error {
  182. query.Result = make([]*m.TeamDTO, 0)
  183. var sql bytes.Buffer
  184. sql.WriteString(getTeamSelectSqlBase())
  185. sql.WriteString(` INNER JOIN team_member on team.id = team_member.team_id`)
  186. sql.WriteString(` WHERE team.org_id = ? and team_member.user_id = ?`)
  187. err := x.SQL(sql.String(), query.OrgId, query.UserId).Find(&query.Result)
  188. return err
  189. }
  190. // AddTeamMember adds a user to a team
  191. func AddTeamMember(cmd *m.AddTeamMemberCommand) error {
  192. return inTransaction(func(sess *DBSession) error {
  193. if res, err := sess.Query("SELECT 1 from team_member WHERE org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId); err != nil {
  194. return err
  195. } else if len(res) == 1 {
  196. return m.ErrTeamMemberAlreadyAdded
  197. }
  198. if _, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  199. return err
  200. }
  201. entity := m.TeamMember{
  202. OrgId: cmd.OrgId,
  203. TeamId: cmd.TeamId,
  204. UserId: cmd.UserId,
  205. External: cmd.External,
  206. Created: time.Now(),
  207. Updated: time.Now(),
  208. Permission: cmd.Permission,
  209. }
  210. _, err := sess.Insert(&entity)
  211. return err
  212. })
  213. }
  214. func getTeamMember(sess *DBSession, orgId int64, teamId int64, userId int64) (m.TeamMember, error) {
  215. rawSql := `SELECT * FROM team_member WHERE org_id=? and team_id=? and user_id=?`
  216. var member m.TeamMember
  217. exists, err := sess.SQL(rawSql, orgId, teamId, userId).Get(&member)
  218. if err != nil {
  219. return member, err
  220. }
  221. if !exists {
  222. return member, m.ErrTeamMemberNotFound
  223. }
  224. return member, nil
  225. }
  226. // UpdateTeamMember updates a team member
  227. func UpdateTeamMember(cmd *m.UpdateTeamMemberCommand) error {
  228. return inTransaction(func(sess *DBSession) error {
  229. member, err := getTeamMember(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  230. if err != nil {
  231. return err
  232. }
  233. if cmd.ProtectLastAdmin {
  234. _, err := isLastAdmin(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  235. if err != nil {
  236. return err
  237. }
  238. }
  239. if cmd.Permission != m.PERMISSION_ADMIN { // make sure we don't get invalid permission levels in store
  240. cmd.Permission = 0
  241. }
  242. member.Permission = cmd.Permission
  243. _, err = sess.Cols("permission").Where("org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId).Update(member)
  244. return err
  245. })
  246. }
  247. // RemoveTeamMember removes a member from a team
  248. func RemoveTeamMember(cmd *m.RemoveTeamMemberCommand) error {
  249. return inTransaction(func(sess *DBSession) error {
  250. if _, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  251. return err
  252. }
  253. if cmd.ProtectLastAdmin {
  254. _, err := isLastAdmin(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  255. if err != nil {
  256. return err
  257. }
  258. }
  259. var rawSql = "DELETE FROM team_member WHERE org_id=? and team_id=? and user_id=?"
  260. res, err := sess.Exec(rawSql, cmd.OrgId, cmd.TeamId, cmd.UserId)
  261. if err != nil {
  262. return err
  263. }
  264. rows, err := res.RowsAffected()
  265. if rows == 0 {
  266. return m.ErrTeamMemberNotFound
  267. }
  268. return err
  269. })
  270. }
  271. func isLastAdmin(sess *DBSession, orgId int64, teamId int64, userId int64) (bool, error) {
  272. rawSql := "SELECT user_id FROM team_member WHERE org_id=? and team_id=? and permission=?"
  273. userIds := []*int64{}
  274. err := sess.SQL(rawSql, orgId, teamId, m.PERMISSION_ADMIN).Find(&userIds)
  275. if err != nil {
  276. return false, err
  277. }
  278. isAdmin := false
  279. for _, adminId := range userIds {
  280. if userId == *adminId {
  281. isAdmin = true
  282. break
  283. }
  284. }
  285. if isAdmin && len(userIds) == 1 {
  286. return true, m.ErrLastTeamAdmin
  287. }
  288. return false, err
  289. }
  290. // GetTeamMembers return a list of members for the specified team
  291. func GetTeamMembers(query *m.GetTeamMembersQuery) error {
  292. query.Result = make([]*m.TeamMemberDTO, 0)
  293. sess := x.Table("team_member")
  294. sess.Join("INNER", x.Dialect().Quote("user"), fmt.Sprintf("team_member.user_id=%s.id", x.Dialect().Quote("user")))
  295. if query.OrgId != 0 {
  296. sess.Where("team_member.org_id=?", query.OrgId)
  297. }
  298. if query.TeamId != 0 {
  299. sess.Where("team_member.team_id=?", query.TeamId)
  300. }
  301. if query.UserId != 0 {
  302. sess.Where("team_member.user_id=?", query.UserId)
  303. }
  304. if query.External {
  305. sess.Where("team_member.external=?", dialect.BooleanStr(true))
  306. }
  307. sess.Cols("team_member.org_id", "team_member.team_id", "team_member.user_id", "user.email", "user.login", "team_member.external", "team_member.permission")
  308. sess.Asc("user.login", "user.email")
  309. err := sess.Find(&query.Result)
  310. return err
  311. }