dashboard.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/infra/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  22. bus.AddHandler("sql", GetDashboardsBySlug)
  23. bus.AddHandler("sql", ValidateDashboardBeforeSave)
  24. bus.AddHandler("sql", HasEditPermissionInFolders)
  25. }
  26. var generateNewUid func() string = util.GenerateShortUID
  27. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  28. return inTransaction(func(sess *DBSession) error {
  29. return saveDashboard(sess, cmd)
  30. })
  31. }
  32. func saveDashboard(sess *DBSession, cmd *m.SaveDashboardCommand) error {
  33. dash := cmd.GetDashboardModel()
  34. userId := cmd.UserId
  35. if userId == 0 {
  36. userId = -1
  37. }
  38. if dash.Id > 0 {
  39. var existing m.Dashboard
  40. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  41. if err != nil {
  42. return err
  43. }
  44. if !dashWithIdExists {
  45. return m.ErrDashboardNotFound
  46. }
  47. // check for is someone else has written in between
  48. if dash.Version != existing.Version {
  49. if cmd.Overwrite {
  50. dash.SetVersion(existing.Version)
  51. } else {
  52. return m.ErrDashboardVersionMismatch
  53. }
  54. }
  55. // do not allow plugin dashboard updates without overwrite flag
  56. if existing.PluginId != "" && !cmd.Overwrite {
  57. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  58. }
  59. }
  60. if dash.Uid == "" {
  61. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  62. if err != nil {
  63. return err
  64. }
  65. dash.SetUid(uid)
  66. }
  67. parentVersion := dash.Version
  68. var affectedRows int64
  69. var err error
  70. if dash.Id == 0 {
  71. dash.SetVersion(1)
  72. dash.Created = time.Now()
  73. dash.CreatedBy = userId
  74. dash.Updated = time.Now()
  75. dash.UpdatedBy = userId
  76. metrics.M_Api_Dashboard_Insert.Inc()
  77. affectedRows, err = sess.Insert(dash)
  78. } else {
  79. dash.SetVersion(dash.Version + 1)
  80. if !cmd.UpdatedAt.IsZero() {
  81. dash.Updated = cmd.UpdatedAt
  82. } else {
  83. dash.Updated = time.Now()
  84. }
  85. dash.UpdatedBy = userId
  86. affectedRows, err = sess.MustCols("folder_id").ID(dash.Id).Update(dash)
  87. }
  88. if err != nil {
  89. return err
  90. }
  91. if affectedRows == 0 {
  92. return m.ErrDashboardNotFound
  93. }
  94. dashVersion := &m.DashboardVersion{
  95. DashboardId: dash.Id,
  96. ParentVersion: parentVersion,
  97. RestoredFrom: cmd.RestoredFrom,
  98. Version: dash.Version,
  99. Created: time.Now(),
  100. CreatedBy: dash.UpdatedBy,
  101. Message: cmd.Message,
  102. Data: dash.Data,
  103. }
  104. // insert version entry
  105. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  106. return err
  107. } else if affectedRows == 0 {
  108. return m.ErrDashboardNotFound
  109. }
  110. // delete existing tags
  111. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  112. if err != nil {
  113. return err
  114. }
  115. // insert new tags
  116. tags := dash.GetTags()
  117. if len(tags) > 0 {
  118. for _, tag := range tags {
  119. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  120. return err
  121. }
  122. }
  123. }
  124. cmd.Result = dash
  125. return err
  126. }
  127. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  128. for i := 0; i < 3; i++ {
  129. uid := generateNewUid()
  130. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&m.Dashboard{})
  131. if err != nil {
  132. return "", err
  133. }
  134. if !exists {
  135. return uid, nil
  136. }
  137. }
  138. return "", m.ErrDashboardFailedGenerateUniqueUid
  139. }
  140. func GetDashboard(query *m.GetDashboardQuery) error {
  141. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  142. has, err := x.Get(&dashboard)
  143. if err != nil {
  144. return err
  145. } else if !has {
  146. return m.ErrDashboardNotFound
  147. }
  148. dashboard.SetId(dashboard.Id)
  149. dashboard.SetUid(dashboard.Uid)
  150. query.Result = &dashboard
  151. return nil
  152. }
  153. type DashboardSearchProjection struct {
  154. Id int64
  155. Uid string
  156. Title string
  157. Slug string
  158. Term string
  159. IsFolder bool
  160. FolderId int64
  161. FolderUid string
  162. FolderSlug string
  163. FolderTitle string
  164. }
  165. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  166. limit := query.Limit
  167. if limit == 0 {
  168. limit = 1000
  169. }
  170. sb := NewSearchBuilder(query.SignedInUser, limit, query.Permission).
  171. WithTags(query.Tags).
  172. WithDashboardIdsIn(query.DashboardIds)
  173. if query.IsStarred {
  174. sb.IsStarred()
  175. }
  176. if len(query.Title) > 0 {
  177. sb.WithTitle(query.Title)
  178. }
  179. if len(query.Type) > 0 {
  180. sb.WithType(query.Type)
  181. }
  182. if len(query.FolderIds) > 0 {
  183. sb.WithFolderIds(query.FolderIds)
  184. }
  185. var res []DashboardSearchProjection
  186. sql, params := sb.ToSql()
  187. err := x.SQL(sql, params...).Find(&res)
  188. if err != nil {
  189. return nil, err
  190. }
  191. return res, nil
  192. }
  193. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  194. res, err := findDashboards(query)
  195. if err != nil {
  196. return err
  197. }
  198. makeQueryResult(query, res)
  199. return nil
  200. }
  201. func getHitType(item DashboardSearchProjection) search.HitType {
  202. var hitType search.HitType
  203. if item.IsFolder {
  204. hitType = search.DashHitFolder
  205. } else {
  206. hitType = search.DashHitDB
  207. }
  208. return hitType
  209. }
  210. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  211. query.Result = make([]*search.Hit, 0)
  212. hits := make(map[int64]*search.Hit)
  213. for _, item := range res {
  214. hit, exists := hits[item.Id]
  215. if !exists {
  216. hit = &search.Hit{
  217. Id: item.Id,
  218. Uid: item.Uid,
  219. Title: item.Title,
  220. Uri: "db/" + item.Slug,
  221. Url: m.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  222. Type: getHitType(item),
  223. FolderId: item.FolderId,
  224. FolderUid: item.FolderUid,
  225. FolderTitle: item.FolderTitle,
  226. Tags: []string{},
  227. }
  228. if item.FolderId > 0 {
  229. hit.FolderUrl = m.GetFolderUrl(item.FolderUid, item.FolderSlug)
  230. }
  231. query.Result = append(query.Result, hit)
  232. hits[item.Id] = hit
  233. }
  234. if len(item.Term) > 0 {
  235. hit.Tags = append(hit.Tags, item.Term)
  236. }
  237. }
  238. }
  239. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  240. sql := `SELECT
  241. COUNT(*) as count,
  242. term
  243. FROM dashboard
  244. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  245. WHERE dashboard.org_id=?
  246. GROUP BY term
  247. ORDER BY term`
  248. query.Result = make([]*m.DashboardTagCloudItem, 0)
  249. sess := x.SQL(sql, query.OrgId)
  250. err := sess.Find(&query.Result)
  251. return err
  252. }
  253. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  254. return inTransaction(func(sess *DBSession) error {
  255. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  256. has, err := sess.Get(&dashboard)
  257. if err != nil {
  258. return err
  259. } else if !has {
  260. return m.ErrDashboardNotFound
  261. }
  262. deletes := []string{
  263. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  264. "DELETE FROM star WHERE dashboard_id = ? ",
  265. "DELETE FROM dashboard WHERE id = ?",
  266. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  267. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  268. "DELETE FROM annotation WHERE dashboard_id = ?",
  269. "DELETE FROM dashboard_provisioning WHERE dashboard_id = ?",
  270. }
  271. if dashboard.IsFolder {
  272. deletes = append(deletes, "DELETE FROM dashboard_provisioning WHERE dashboard_id in (select id from dashboard where folder_id = ?)")
  273. deletes = append(deletes, "DELETE FROM dashboard WHERE folder_id = ?")
  274. dashIds := []struct {
  275. Id int64
  276. }{}
  277. err := sess.SQL("select id from dashboard where folder_id = ?", dashboard.Id).Find(&dashIds)
  278. if err != nil {
  279. return err
  280. }
  281. for _, id := range dashIds {
  282. if err := deleteAlertDefinition(id.Id, sess); err != nil {
  283. return nil
  284. }
  285. }
  286. }
  287. if err := deleteAlertDefinition(dashboard.Id, sess); err != nil {
  288. return nil
  289. }
  290. for _, sql := range deletes {
  291. _, err := sess.Exec(sql, dashboard.Id)
  292. if err != nil {
  293. return err
  294. }
  295. }
  296. return nil
  297. })
  298. }
  299. func GetDashboards(query *m.GetDashboardsQuery) error {
  300. if len(query.DashboardIds) == 0 {
  301. return m.ErrCommandValidationFailed
  302. }
  303. var dashboards = make([]*m.Dashboard, 0)
  304. err := x.In("id", query.DashboardIds).Find(&dashboards)
  305. query.Result = dashboards
  306. return err
  307. }
  308. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  309. // The function takes in a list of dashboard ids and the user id and role
  310. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  311. if len(query.DashboardIds) == 0 {
  312. return m.ErrCommandValidationFailed
  313. }
  314. if query.OrgRole == m.ROLE_ADMIN {
  315. var permissions = make([]*m.DashboardPermissionForUser, 0)
  316. for _, d := range query.DashboardIds {
  317. permissions = append(permissions, &m.DashboardPermissionForUser{
  318. DashboardId: d,
  319. Permission: m.PERMISSION_ADMIN,
  320. PermissionName: m.PERMISSION_ADMIN.String(),
  321. })
  322. }
  323. query.Result = permissions
  324. return nil
  325. }
  326. params := make([]interface{}, 0)
  327. // check dashboards that have ACLs via user id, team id or role
  328. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  329. FROM dashboard AS d
  330. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  331. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  332. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  333. `
  334. params = append(params, query.UserId)
  335. //check the user's role for dashboards that do not have hasAcl set
  336. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  337. params = append(params, query.UserId)
  338. params = append(params, query.OrgId)
  339. sql += `
  340. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  341. UNION SELECT 2 AS permission, 'Editor' AS role
  342. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  343. WHERE
  344. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  345. for _, id := range query.DashboardIds {
  346. params = append(params, id)
  347. }
  348. sql += ` AND
  349. d.org_id = ? AND
  350. (
  351. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  352. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  353. )
  354. group by d.id
  355. order by d.id asc`
  356. params = append(params, query.OrgId)
  357. params = append(params, dialect.BooleanStr(true))
  358. params = append(params, query.UserId)
  359. params = append(params, query.UserId)
  360. params = append(params, dialect.BooleanStr(false))
  361. err := x.SQL(sql, params...).Find(&query.Result)
  362. for _, p := range query.Result {
  363. p.PermissionName = p.Permission.String()
  364. }
  365. return err
  366. }
  367. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  368. var dashboards = make([]*m.Dashboard, 0)
  369. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  370. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  371. query.Result = dashboards
  372. return err
  373. }
  374. type DashboardSlugDTO struct {
  375. Slug string
  376. }
  377. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  378. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  379. var slug = DashboardSlugDTO{}
  380. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  381. if err != nil {
  382. return err
  383. } else if !exists {
  384. return m.ErrDashboardNotFound
  385. }
  386. query.Result = slug.Slug
  387. return nil
  388. }
  389. func GetDashboardsBySlug(query *m.GetDashboardsBySlugQuery) error {
  390. var dashboards []*m.Dashboard
  391. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  392. return err
  393. }
  394. query.Result = dashboards
  395. return nil
  396. }
  397. func GetDashboardUIDById(query *m.GetDashboardRefByIdQuery) error {
  398. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  399. us := &m.DashboardRef{}
  400. exists, err := x.SQL(rawSql, query.Id).Get(us)
  401. if err != nil {
  402. return err
  403. } else if !exists {
  404. return m.ErrDashboardNotFound
  405. }
  406. query.Result = us
  407. return nil
  408. }
  409. func getExistingDashboardByIdOrUidForUpdate(sess *DBSession, cmd *m.ValidateDashboardBeforeSaveCommand) (err error) {
  410. dash := cmd.Dashboard
  411. dashWithIdExists := false
  412. var existingById m.Dashboard
  413. if dash.Id > 0 {
  414. dashWithIdExists, err = sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existingById)
  415. if err != nil {
  416. return err
  417. }
  418. if !dashWithIdExists {
  419. return m.ErrDashboardNotFound
  420. }
  421. if dash.Uid == "" {
  422. dash.SetUid(existingById.Uid)
  423. }
  424. }
  425. dashWithUidExists := false
  426. var existingByUid m.Dashboard
  427. if dash.Uid != "" {
  428. dashWithUidExists, err = sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&existingByUid)
  429. if err != nil {
  430. return err
  431. }
  432. }
  433. if dash.FolderId > 0 {
  434. var existingFolder m.Dashboard
  435. folderExists, folderErr := sess.Where("org_id=? AND id=? AND is_folder=?", dash.OrgId, dash.FolderId, dialect.BooleanStr(true)).Get(&existingFolder)
  436. if folderErr != nil {
  437. return folderErr
  438. }
  439. if !folderExists {
  440. return m.ErrDashboardFolderNotFound
  441. }
  442. }
  443. if !dashWithIdExists && !dashWithUidExists {
  444. return nil
  445. }
  446. if dashWithIdExists && dashWithUidExists && existingById.Id != existingByUid.Id {
  447. return m.ErrDashboardWithSameUIDExists
  448. }
  449. existing := existingById
  450. if !dashWithIdExists && dashWithUidExists {
  451. dash.SetId(existingByUid.Id)
  452. dash.SetUid(existingByUid.Uid)
  453. existing = existingByUid
  454. if !dash.IsFolder {
  455. cmd.Result.IsParentFolderChanged = true
  456. }
  457. }
  458. if (existing.IsFolder && !dash.IsFolder) ||
  459. (!existing.IsFolder && dash.IsFolder) {
  460. return m.ErrDashboardTypeMismatch
  461. }
  462. if !dash.IsFolder && dash.FolderId != existing.FolderId {
  463. cmd.Result.IsParentFolderChanged = true
  464. }
  465. // check for is someone else has written in between
  466. if dash.Version != existing.Version {
  467. if cmd.Overwrite {
  468. dash.SetVersion(existing.Version)
  469. } else {
  470. return m.ErrDashboardVersionMismatch
  471. }
  472. }
  473. // do not allow plugin dashboard updates without overwrite flag
  474. if existing.PluginId != "" && !cmd.Overwrite {
  475. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  476. }
  477. return nil
  478. }
  479. func getExistingDashboardByTitleAndFolder(sess *DBSession, cmd *m.ValidateDashboardBeforeSaveCommand) error {
  480. dash := cmd.Dashboard
  481. var existing m.Dashboard
  482. exists, err := sess.Where("org_id=? AND slug=? AND (is_folder=? OR folder_id=?)", dash.OrgId, dash.Slug, dialect.BooleanStr(true), dash.FolderId).Get(&existing)
  483. if err != nil {
  484. return err
  485. }
  486. if exists && dash.Id != existing.Id {
  487. if existing.IsFolder && !dash.IsFolder {
  488. return m.ErrDashboardWithSameNameAsFolder
  489. }
  490. if !existing.IsFolder && dash.IsFolder {
  491. return m.ErrDashboardFolderWithSameNameAsDashboard
  492. }
  493. if !dash.IsFolder && (dash.FolderId != existing.FolderId || dash.Id == 0) {
  494. cmd.Result.IsParentFolderChanged = true
  495. }
  496. if cmd.Overwrite {
  497. dash.SetId(existing.Id)
  498. dash.SetUid(existing.Uid)
  499. dash.SetVersion(existing.Version)
  500. } else {
  501. return m.ErrDashboardWithSameNameInFolderExists
  502. }
  503. }
  504. return nil
  505. }
  506. func ValidateDashboardBeforeSave(cmd *m.ValidateDashboardBeforeSaveCommand) (err error) {
  507. cmd.Result = &m.ValidateDashboardBeforeSaveResult{}
  508. return inTransaction(func(sess *DBSession) error {
  509. if err = getExistingDashboardByIdOrUidForUpdate(sess, cmd); err != nil {
  510. return err
  511. }
  512. if err = getExistingDashboardByTitleAndFolder(sess, cmd); err != nil {
  513. return err
  514. }
  515. return nil
  516. })
  517. }
  518. func HasEditPermissionInFolders(query *m.HasEditPermissionInFoldersQuery) error {
  519. if query.SignedInUser.HasRole(m.ROLE_EDITOR) {
  520. query.Result = true
  521. return nil
  522. }
  523. builder := &SqlBuilder{}
  524. builder.Write("SELECT COUNT(dashboard.id) AS count FROM dashboard WHERE dashboard.org_id = ? AND dashboard.is_folder = ?", query.SignedInUser.OrgId, dialect.BooleanStr(true))
  525. builder.writeDashboardPermissionFilter(query.SignedInUser, m.PERMISSION_EDIT)
  526. type folderCount struct {
  527. Count int64
  528. }
  529. resp := make([]*folderCount, 0)
  530. if err := x.SQL(builder.GetSqlString(), builder.params...).Find(&resp); err != nil {
  531. return err
  532. }
  533. query.Result = len(resp) > 0 && resp[0].Count > 0
  534. return nil
  535. }