guardian.go 2.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
  1. package guardian
  2. import (
  3. "github.com/grafana/grafana/pkg/bus"
  4. "github.com/grafana/grafana/pkg/log"
  5. m "github.com/grafana/grafana/pkg/models"
  6. )
  7. type DashboardGuardian struct {
  8. user *m.SignedInUser
  9. dashId int64
  10. orgId int64
  11. acl []*m.DashboardAcl
  12. groups []*m.UserGroup
  13. log log.Logger
  14. }
  15. func NewDashboardGuardian(dashId int64, orgId int64, user *m.SignedInUser) *DashboardGuardian {
  16. return &DashboardGuardian{
  17. user: user,
  18. dashId: dashId,
  19. orgId: orgId,
  20. log: log.New("guardians.dashboard"),
  21. }
  22. }
  23. func (g *DashboardGuardian) CanSave() (bool, error) {
  24. return g.HasPermission(m.PERMISSION_EDIT, m.ROLE_EDITOR)
  25. }
  26. func (g *DashboardGuardian) CanEdit() (bool, error) {
  27. return g.HasPermission(m.PERMISSION_READ_ONLY_EDIT, m.ROLE_READ_ONLY_EDITOR)
  28. }
  29. func (g *DashboardGuardian) CanView() (bool, error) {
  30. return g.HasPermission(m.PERMISSION_VIEW, m.ROLE_VIEWER)
  31. }
  32. func (g *DashboardGuardian) HasPermission(permission m.PermissionType, fallbackRole m.RoleType) (bool, error) {
  33. if g.user.OrgRole == m.ROLE_ADMIN {
  34. return true, nil
  35. }
  36. acl, err := g.getAcl()
  37. if err != nil {
  38. return false, err
  39. }
  40. // if no acl use org role to determine permission
  41. if len(acl) == 0 {
  42. return g.user.HasRole(fallbackRole), nil
  43. }
  44. userGroups, err := g.getUserGroups()
  45. if err != nil {
  46. return false, err
  47. }
  48. for _, p := range acl {
  49. if p.UserId == g.user.UserId && p.Permissions >= permission {
  50. return true, nil
  51. }
  52. for _, ug := range userGroups {
  53. if ug.Id == p.UserGroupId && p.Permissions >= permission {
  54. return true, nil
  55. }
  56. }
  57. }
  58. return false, nil
  59. }
  60. // Returns dashboard acl
  61. func (g *DashboardGuardian) getAcl() ([]*m.DashboardAcl, error) {
  62. if g.acl != nil {
  63. return g.acl, nil
  64. }
  65. query := m.GetInheritedDashboardAclQuery{DashboardId: g.dashId, OrgId: g.orgId}
  66. if err := bus.Dispatch(&query); err != nil {
  67. return nil, err
  68. }
  69. g.acl = query.Result
  70. return g.acl, nil
  71. }
  72. func (g *DashboardGuardian) getUserGroups() ([]*m.UserGroup, error) {
  73. if g.groups != nil {
  74. return g.groups, nil
  75. }
  76. query := m.GetUserGroupsByUserQuery{UserId: g.user.UserId}
  77. err := bus.Dispatch(&query)
  78. g.groups = query.Result
  79. return query.Result, err
  80. }