dashboard.go 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/infra/metrics"
  7. "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  22. bus.AddHandler("sql", GetDashboardsBySlug)
  23. bus.AddHandler("sql", ValidateDashboardBeforeSave)
  24. bus.AddHandler("sql", HasEditPermissionInFolders)
  25. bus.AddHandler("sql", HasAdminPermissionInFolders)
  26. }
  27. var generateNewUid func() string = util.GenerateShortUID
  28. func SaveDashboard(cmd *models.SaveDashboardCommand) error {
  29. return inTransaction(func(sess *DBSession) error {
  30. return saveDashboard(sess, cmd)
  31. })
  32. }
  33. func saveDashboard(sess *DBSession, cmd *models.SaveDashboardCommand) error {
  34. dash := cmd.GetDashboardModel()
  35. userId := cmd.UserId
  36. if userId == 0 {
  37. userId = -1
  38. }
  39. if dash.Id > 0 {
  40. var existing models.Dashboard
  41. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  42. if err != nil {
  43. return err
  44. }
  45. if !dashWithIdExists {
  46. return models.ErrDashboardNotFound
  47. }
  48. // check for is someone else has written in between
  49. if dash.Version != existing.Version {
  50. if cmd.Overwrite {
  51. dash.SetVersion(existing.Version)
  52. } else {
  53. return models.ErrDashboardVersionMismatch
  54. }
  55. }
  56. // do not allow plugin dashboard updates without overwrite flag
  57. if existing.PluginId != "" && !cmd.Overwrite {
  58. return models.UpdatePluginDashboardError{PluginId: existing.PluginId}
  59. }
  60. }
  61. if dash.Uid == "" {
  62. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  63. if err != nil {
  64. return err
  65. }
  66. dash.SetUid(uid)
  67. }
  68. parentVersion := dash.Version
  69. var affectedRows int64
  70. var err error
  71. if dash.Id == 0 {
  72. dash.SetVersion(1)
  73. dash.Created = time.Now()
  74. dash.CreatedBy = userId
  75. dash.Updated = time.Now()
  76. dash.UpdatedBy = userId
  77. metrics.MApiDashboardInsert.Inc()
  78. affectedRows, err = sess.Insert(dash)
  79. } else {
  80. dash.SetVersion(dash.Version + 1)
  81. if !cmd.UpdatedAt.IsZero() {
  82. dash.Updated = cmd.UpdatedAt
  83. } else {
  84. dash.Updated = time.Now()
  85. }
  86. dash.UpdatedBy = userId
  87. affectedRows, err = sess.MustCols("folder_id").ID(dash.Id).Update(dash)
  88. }
  89. if err != nil {
  90. return err
  91. }
  92. if affectedRows == 0 {
  93. return models.ErrDashboardNotFound
  94. }
  95. dashVersion := &models.DashboardVersion{
  96. DashboardId: dash.Id,
  97. ParentVersion: parentVersion,
  98. RestoredFrom: cmd.RestoredFrom,
  99. Version: dash.Version,
  100. Created: time.Now(),
  101. CreatedBy: dash.UpdatedBy,
  102. Message: cmd.Message,
  103. Data: dash.Data,
  104. }
  105. // insert version entry
  106. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  107. return err
  108. } else if affectedRows == 0 {
  109. return models.ErrDashboardNotFound
  110. }
  111. // delete existing tags
  112. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  113. if err != nil {
  114. return err
  115. }
  116. // insert new tags
  117. tags := dash.GetTags()
  118. if len(tags) > 0 {
  119. for _, tag := range tags {
  120. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  121. return err
  122. }
  123. }
  124. }
  125. cmd.Result = dash
  126. return err
  127. }
  128. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  129. for i := 0; i < 3; i++ {
  130. uid := generateNewUid()
  131. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&models.Dashboard{})
  132. if err != nil {
  133. return "", err
  134. }
  135. if !exists {
  136. return uid, nil
  137. }
  138. }
  139. return "", models.ErrDashboardFailedGenerateUniqueUid
  140. }
  141. func GetDashboard(query *models.GetDashboardQuery) error {
  142. dashboard := models.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  143. has, err := x.Get(&dashboard)
  144. if err != nil {
  145. return err
  146. } else if !has {
  147. return models.ErrDashboardNotFound
  148. }
  149. dashboard.SetId(dashboard.Id)
  150. dashboard.SetUid(dashboard.Uid)
  151. query.Result = &dashboard
  152. return nil
  153. }
  154. type DashboardSearchProjection struct {
  155. Id int64
  156. Uid string
  157. Title string
  158. Slug string
  159. Term string
  160. IsFolder bool
  161. FolderId int64
  162. FolderUid string
  163. FolderSlug string
  164. FolderTitle string
  165. }
  166. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  167. sb := NewSearchBuilder(query.SignedInUser, query.Limit, query.Page, query.Permission).
  168. WithTags(query.Tags).
  169. WithDashboardIdsIn(query.DashboardIds)
  170. if query.IsStarred {
  171. sb.IsStarred()
  172. }
  173. if len(query.Title) > 0 {
  174. sb.WithTitle(query.Title)
  175. }
  176. if len(query.Type) > 0 {
  177. sb.WithType(query.Type)
  178. }
  179. if len(query.FolderIds) > 0 {
  180. sb.WithFolderIds(query.FolderIds)
  181. }
  182. var res []DashboardSearchProjection
  183. sql, params := sb.ToSql()
  184. err := x.SQL(sql, params...).Find(&res)
  185. if err != nil {
  186. return nil, err
  187. }
  188. return res, nil
  189. }
  190. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  191. res, err := findDashboards(query)
  192. if err != nil {
  193. return err
  194. }
  195. makeQueryResult(query, res)
  196. return nil
  197. }
  198. func getHitType(item DashboardSearchProjection) search.HitType {
  199. var hitType search.HitType
  200. if item.IsFolder {
  201. hitType = search.DashHitFolder
  202. } else {
  203. hitType = search.DashHitDB
  204. }
  205. return hitType
  206. }
  207. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  208. query.Result = make([]*search.Hit, 0)
  209. hits := make(map[int64]*search.Hit)
  210. for _, item := range res {
  211. hit, exists := hits[item.Id]
  212. if !exists {
  213. hit = &search.Hit{
  214. Id: item.Id,
  215. Uid: item.Uid,
  216. Title: item.Title,
  217. Uri: "db/" + item.Slug,
  218. Url: models.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  219. Type: getHitType(item),
  220. FolderId: item.FolderId,
  221. FolderUid: item.FolderUid,
  222. FolderTitle: item.FolderTitle,
  223. Tags: []string{},
  224. }
  225. if item.FolderId > 0 {
  226. hit.FolderUrl = models.GetFolderUrl(item.FolderUid, item.FolderSlug)
  227. }
  228. query.Result = append(query.Result, hit)
  229. hits[item.Id] = hit
  230. }
  231. if len(item.Term) > 0 {
  232. hit.Tags = append(hit.Tags, item.Term)
  233. }
  234. }
  235. }
  236. func GetDashboardTags(query *models.GetDashboardTagsQuery) error {
  237. sql := `SELECT
  238. COUNT(*) as count,
  239. term
  240. FROM dashboard
  241. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  242. WHERE dashboard.org_id=?
  243. GROUP BY term
  244. ORDER BY term`
  245. query.Result = make([]*models.DashboardTagCloudItem, 0)
  246. sess := x.SQL(sql, query.OrgId)
  247. err := sess.Find(&query.Result)
  248. return err
  249. }
  250. func DeleteDashboard(cmd *models.DeleteDashboardCommand) error {
  251. return inTransaction(func(sess *DBSession) error {
  252. dashboard := models.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  253. has, err := sess.Get(&dashboard)
  254. if err != nil {
  255. return err
  256. } else if !has {
  257. return models.ErrDashboardNotFound
  258. }
  259. deletes := []string{
  260. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  261. "DELETE FROM star WHERE dashboard_id = ? ",
  262. "DELETE FROM dashboard WHERE id = ?",
  263. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  264. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  265. "DELETE FROM annotation WHERE dashboard_id = ?",
  266. "DELETE FROM dashboard_provisioning WHERE dashboard_id = ?",
  267. }
  268. if dashboard.IsFolder {
  269. deletes = append(deletes, "DELETE FROM dashboard_provisioning WHERE dashboard_id in (select id from dashboard where folder_id = ?)")
  270. deletes = append(deletes, "DELETE FROM dashboard WHERE folder_id = ?")
  271. dashIds := []struct {
  272. Id int64
  273. }{}
  274. err := sess.SQL("select id from dashboard where folder_id = ?", dashboard.Id).Find(&dashIds)
  275. if err != nil {
  276. return err
  277. }
  278. for _, id := range dashIds {
  279. if err := deleteAlertDefinition(id.Id, sess); err != nil {
  280. return nil
  281. }
  282. }
  283. }
  284. if err := deleteAlertDefinition(dashboard.Id, sess); err != nil {
  285. return nil
  286. }
  287. for _, sql := range deletes {
  288. _, err := sess.Exec(sql, dashboard.Id)
  289. if err != nil {
  290. return err
  291. }
  292. }
  293. return nil
  294. })
  295. }
  296. func GetDashboards(query *models.GetDashboardsQuery) error {
  297. if len(query.DashboardIds) == 0 {
  298. return models.ErrCommandValidationFailed
  299. }
  300. var dashboards = make([]*models.Dashboard, 0)
  301. err := x.In("id", query.DashboardIds).Find(&dashboards)
  302. query.Result = dashboards
  303. return err
  304. }
  305. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  306. // The function takes in a list of dashboard ids and the user id and role
  307. func GetDashboardPermissionsForUser(query *models.GetDashboardPermissionsForUserQuery) error {
  308. if len(query.DashboardIds) == 0 {
  309. return models.ErrCommandValidationFailed
  310. }
  311. if query.OrgRole == models.ROLE_ADMIN {
  312. var permissions = make([]*models.DashboardPermissionForUser, 0)
  313. for _, d := range query.DashboardIds {
  314. permissions = append(permissions, &models.DashboardPermissionForUser{
  315. DashboardId: d,
  316. Permission: models.PERMISSION_ADMIN,
  317. PermissionName: models.PERMISSION_ADMIN.String(),
  318. })
  319. }
  320. query.Result = permissions
  321. return nil
  322. }
  323. params := make([]interface{}, 0)
  324. // check dashboards that have ACLs via user id, team id or role
  325. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  326. FROM dashboard AS d
  327. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  328. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  329. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  330. `
  331. params = append(params, query.UserId)
  332. //check the user's role for dashboards that do not have hasAcl set
  333. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  334. params = append(params, query.UserId)
  335. params = append(params, query.OrgId)
  336. sql += `
  337. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  338. UNION SELECT 2 AS permission, 'Editor' AS role
  339. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  340. WHERE
  341. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  342. for _, id := range query.DashboardIds {
  343. params = append(params, id)
  344. }
  345. sql += ` AND
  346. d.org_id = ? AND
  347. (
  348. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  349. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  350. )
  351. group by d.id
  352. order by d.id asc`
  353. params = append(params, query.OrgId)
  354. params = append(params, dialect.BooleanStr(true))
  355. params = append(params, query.UserId)
  356. params = append(params, query.UserId)
  357. params = append(params, dialect.BooleanStr(false))
  358. err := x.SQL(sql, params...).Find(&query.Result)
  359. for _, p := range query.Result {
  360. p.PermissionName = p.Permission.String()
  361. }
  362. return err
  363. }
  364. func GetDashboardsByPluginId(query *models.GetDashboardsByPluginIdQuery) error {
  365. var dashboards = make([]*models.Dashboard, 0)
  366. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  367. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  368. query.Result = dashboards
  369. return err
  370. }
  371. type DashboardSlugDTO struct {
  372. Slug string
  373. }
  374. func GetDashboardSlugById(query *models.GetDashboardSlugByIdQuery) error {
  375. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  376. var slug = DashboardSlugDTO{}
  377. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  378. if err != nil {
  379. return err
  380. } else if !exists {
  381. return models.ErrDashboardNotFound
  382. }
  383. query.Result = slug.Slug
  384. return nil
  385. }
  386. func GetDashboardsBySlug(query *models.GetDashboardsBySlugQuery) error {
  387. var dashboards []*models.Dashboard
  388. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  389. return err
  390. }
  391. query.Result = dashboards
  392. return nil
  393. }
  394. func GetDashboardUIDById(query *models.GetDashboardRefByIdQuery) error {
  395. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  396. us := &models.DashboardRef{}
  397. exists, err := x.SQL(rawSql, query.Id).Get(us)
  398. if err != nil {
  399. return err
  400. } else if !exists {
  401. return models.ErrDashboardNotFound
  402. }
  403. query.Result = us
  404. return nil
  405. }
  406. func getExistingDashboardByIdOrUidForUpdate(sess *DBSession, cmd *models.ValidateDashboardBeforeSaveCommand) (err error) {
  407. dash := cmd.Dashboard
  408. dashWithIdExists := false
  409. var existingById models.Dashboard
  410. if dash.Id > 0 {
  411. dashWithIdExists, err = sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existingById)
  412. if err != nil {
  413. return err
  414. }
  415. if !dashWithIdExists {
  416. return models.ErrDashboardNotFound
  417. }
  418. if dash.Uid == "" {
  419. dash.SetUid(existingById.Uid)
  420. }
  421. }
  422. dashWithUidExists := false
  423. var existingByUid models.Dashboard
  424. if dash.Uid != "" {
  425. dashWithUidExists, err = sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&existingByUid)
  426. if err != nil {
  427. return err
  428. }
  429. }
  430. if dash.FolderId > 0 {
  431. var existingFolder models.Dashboard
  432. folderExists, folderErr := sess.Where("org_id=? AND id=? AND is_folder=?", dash.OrgId, dash.FolderId, dialect.BooleanStr(true)).Get(&existingFolder)
  433. if folderErr != nil {
  434. return folderErr
  435. }
  436. if !folderExists {
  437. return models.ErrDashboardFolderNotFound
  438. }
  439. }
  440. if !dashWithIdExists && !dashWithUidExists {
  441. return nil
  442. }
  443. if dashWithIdExists && dashWithUidExists && existingById.Id != existingByUid.Id {
  444. return models.ErrDashboardWithSameUIDExists
  445. }
  446. existing := existingById
  447. if !dashWithIdExists && dashWithUidExists {
  448. dash.SetId(existingByUid.Id)
  449. dash.SetUid(existingByUid.Uid)
  450. existing = existingByUid
  451. if !dash.IsFolder {
  452. cmd.Result.IsParentFolderChanged = true
  453. }
  454. }
  455. if (existing.IsFolder && !dash.IsFolder) ||
  456. (!existing.IsFolder && dash.IsFolder) {
  457. return models.ErrDashboardTypeMismatch
  458. }
  459. if !dash.IsFolder && dash.FolderId != existing.FolderId {
  460. cmd.Result.IsParentFolderChanged = true
  461. }
  462. // check for is someone else has written in between
  463. if dash.Version != existing.Version {
  464. if cmd.Overwrite {
  465. dash.SetVersion(existing.Version)
  466. } else {
  467. return models.ErrDashboardVersionMismatch
  468. }
  469. }
  470. // do not allow plugin dashboard updates without overwrite flag
  471. if existing.PluginId != "" && !cmd.Overwrite {
  472. return models.UpdatePluginDashboardError{PluginId: existing.PluginId}
  473. }
  474. return nil
  475. }
  476. func getExistingDashboardByTitleAndFolder(sess *DBSession, cmd *models.ValidateDashboardBeforeSaveCommand) error {
  477. dash := cmd.Dashboard
  478. var existing models.Dashboard
  479. exists, err := sess.Where("org_id=? AND slug=? AND (is_folder=? OR folder_id=?)", dash.OrgId, dash.Slug, dialect.BooleanStr(true), dash.FolderId).Get(&existing)
  480. if err != nil {
  481. return err
  482. }
  483. if exists && dash.Id != existing.Id {
  484. if existing.IsFolder && !dash.IsFolder {
  485. return models.ErrDashboardWithSameNameAsFolder
  486. }
  487. if !existing.IsFolder && dash.IsFolder {
  488. return models.ErrDashboardFolderWithSameNameAsDashboard
  489. }
  490. if !dash.IsFolder && (dash.FolderId != existing.FolderId || dash.Id == 0) {
  491. cmd.Result.IsParentFolderChanged = true
  492. }
  493. if cmd.Overwrite {
  494. dash.SetId(existing.Id)
  495. dash.SetUid(existing.Uid)
  496. dash.SetVersion(existing.Version)
  497. } else {
  498. return models.ErrDashboardWithSameNameInFolderExists
  499. }
  500. }
  501. return nil
  502. }
  503. func ValidateDashboardBeforeSave(cmd *models.ValidateDashboardBeforeSaveCommand) (err error) {
  504. cmd.Result = &models.ValidateDashboardBeforeSaveResult{}
  505. return inTransaction(func(sess *DBSession) error {
  506. if err = getExistingDashboardByIdOrUidForUpdate(sess, cmd); err != nil {
  507. return err
  508. }
  509. if err = getExistingDashboardByTitleAndFolder(sess, cmd); err != nil {
  510. return err
  511. }
  512. return nil
  513. })
  514. }
  515. func HasEditPermissionInFolders(query *models.HasEditPermissionInFoldersQuery) error {
  516. if query.SignedInUser.HasRole(models.ROLE_EDITOR) {
  517. query.Result = true
  518. return nil
  519. }
  520. builder := &SqlBuilder{}
  521. builder.Write("SELECT COUNT(dashboard.id) AS count FROM dashboard WHERE dashboard.org_id = ? AND dashboard.is_folder = ?", query.SignedInUser.OrgId, dialect.BooleanStr(true))
  522. builder.writeDashboardPermissionFilter(query.SignedInUser, models.PERMISSION_EDIT)
  523. type folderCount struct {
  524. Count int64
  525. }
  526. resp := make([]*folderCount, 0)
  527. if err := x.SQL(builder.GetSqlString(), builder.params...).Find(&resp); err != nil {
  528. return err
  529. }
  530. query.Result = len(resp) > 0 && resp[0].Count > 0
  531. return nil
  532. }
  533. func HasAdminPermissionInFolders(query *models.HasAdminPermissionInFoldersQuery) error {
  534. if query.SignedInUser.HasRole(models.ROLE_ADMIN) {
  535. query.Result = true
  536. return nil
  537. }
  538. builder := &SqlBuilder{}
  539. builder.Write("SELECT COUNT(dashboard.id) AS count FROM dashboard WHERE dashboard.org_id = ? AND dashboard.is_folder = ?", query.SignedInUser.OrgId, dialect.BooleanStr(true))
  540. builder.writeDashboardPermissionFilter(query.SignedInUser, models.PERMISSION_ADMIN)
  541. type folderCount struct {
  542. Count int64
  543. }
  544. resp := make([]*folderCount, 0)
  545. if err := x.SQL(builder.GetSqlString(), builder.params...).Find(&resp); err != nil {
  546. return err
  547. }
  548. query.Result = len(resp) > 0 && resp[0].Count > 0
  549. return nil
  550. }