team.go 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413
  1. package sqlstore
  2. import (
  3. "bytes"
  4. "fmt"
  5. "time"
  6. "github.com/grafana/grafana/pkg/bus"
  7. "github.com/grafana/grafana/pkg/models"
  8. )
  9. func init() {
  10. bus.AddHandler("sql", CreateTeam)
  11. bus.AddHandler("sql", UpdateTeam)
  12. bus.AddHandler("sql", DeleteTeam)
  13. bus.AddHandler("sql", SearchTeams)
  14. bus.AddHandler("sql", GetTeamById)
  15. bus.AddHandler("sql", GetTeamsByUser)
  16. bus.AddHandler("sql", AddTeamMember)
  17. bus.AddHandler("sql", UpdateTeamMember)
  18. bus.AddHandler("sql", RemoveTeamMember)
  19. bus.AddHandler("sql", GetTeamMembers)
  20. bus.AddHandler("sql", IsAdminOfTeams)
  21. }
  22. func getTeamSearchSqlBase() string {
  23. return `SELECT
  24. team.id as id,
  25. team.org_id,
  26. team.name as name,
  27. team.email as email,
  28. (SELECT COUNT(*) from team_member where team_member.team_id = team.id) as member_count,
  29. team_member.permission
  30. FROM team as team
  31. INNER JOIN team_member on team.id = team_member.team_id AND team_member.user_id = ? `
  32. }
  33. func getTeamSelectSqlBase() string {
  34. return `SELECT
  35. team.id as id,
  36. team.org_id,
  37. team.name as name,
  38. team.email as email,
  39. (SELECT COUNT(*) from team_member where team_member.team_id = team.id) as member_count
  40. FROM team as team `
  41. }
  42. func CreateTeam(cmd *models.CreateTeamCommand) error {
  43. return inTransaction(func(sess *DBSession) error {
  44. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, 0, sess); err != nil {
  45. return err
  46. } else if isNameTaken {
  47. return models.ErrTeamNameTaken
  48. }
  49. team := models.Team{
  50. Name: cmd.Name,
  51. Email: cmd.Email,
  52. OrgId: cmd.OrgId,
  53. Created: time.Now(),
  54. Updated: time.Now(),
  55. }
  56. _, err := sess.Insert(&team)
  57. cmd.Result = team
  58. return err
  59. })
  60. }
  61. func UpdateTeam(cmd *models.UpdateTeamCommand) error {
  62. return inTransaction(func(sess *DBSession) error {
  63. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, cmd.Id, sess); err != nil {
  64. return err
  65. } else if isNameTaken {
  66. return models.ErrTeamNameTaken
  67. }
  68. team := models.Team{
  69. Name: cmd.Name,
  70. Email: cmd.Email,
  71. Updated: time.Now(),
  72. }
  73. sess.MustCols("email")
  74. affectedRows, err := sess.ID(cmd.Id).Update(&team)
  75. if err != nil {
  76. return err
  77. }
  78. if affectedRows == 0 {
  79. return models.ErrTeamNotFound
  80. }
  81. return nil
  82. })
  83. }
  84. // DeleteTeam will delete a team, its member and any permissions connected to the team
  85. func DeleteTeam(cmd *models.DeleteTeamCommand) error {
  86. return inTransaction(func(sess *DBSession) error {
  87. if _, err := teamExists(cmd.OrgId, cmd.Id, sess); err != nil {
  88. return err
  89. }
  90. deletes := []string{
  91. "DELETE FROM team_member WHERE org_id=? and team_id = ?",
  92. "DELETE FROM team WHERE org_id=? and id = ?",
  93. "DELETE FROM dashboard_acl WHERE org_id=? and team_id = ?",
  94. }
  95. for _, sql := range deletes {
  96. _, err := sess.Exec(sql, cmd.OrgId, cmd.Id)
  97. if err != nil {
  98. return err
  99. }
  100. }
  101. return nil
  102. })
  103. }
  104. func teamExists(orgId int64, teamId int64, sess *DBSession) (bool, error) {
  105. if res, err := sess.Query("SELECT 1 from team WHERE org_id=? and id=?", orgId, teamId); err != nil {
  106. return false, err
  107. } else if len(res) != 1 {
  108. return false, models.ErrTeamNotFound
  109. }
  110. return true, nil
  111. }
  112. func isTeamNameTaken(orgId int64, name string, existingId int64, sess *DBSession) (bool, error) {
  113. var team models.Team
  114. exists, err := sess.Where("org_id=? and name=?", orgId, name).Get(&team)
  115. if err != nil {
  116. return false, nil
  117. }
  118. if exists && existingId != team.Id {
  119. return true, nil
  120. }
  121. return false, nil
  122. }
  123. func SearchTeams(query *models.SearchTeamsQuery) error {
  124. query.Result = models.SearchTeamQueryResult{
  125. Teams: make([]*models.TeamDTO, 0),
  126. }
  127. queryWithWildcards := "%" + query.Query + "%"
  128. var sql bytes.Buffer
  129. params := make([]interface{}, 0)
  130. if query.UserIdFilter > 0 {
  131. sql.WriteString(getTeamSearchSqlBase())
  132. params = append(params, query.UserIdFilter)
  133. } else {
  134. sql.WriteString(getTeamSelectSqlBase())
  135. }
  136. sql.WriteString(` WHERE team.org_id = ?`)
  137. params = append(params, query.OrgId)
  138. if query.Query != "" {
  139. sql.WriteString(` and team.name ` + dialect.LikeStr() + ` ?`)
  140. params = append(params, queryWithWildcards)
  141. }
  142. if query.Name != "" {
  143. sql.WriteString(` and team.name = ?`)
  144. params = append(params, query.Name)
  145. }
  146. sql.WriteString(` order by team.name asc`)
  147. if query.Limit != 0 {
  148. offset := query.Limit * (query.Page - 1)
  149. sql.WriteString(dialect.LimitOffset(int64(query.Limit), int64(offset)))
  150. }
  151. if err := x.SQL(sql.String(), params...).Find(&query.Result.Teams); err != nil {
  152. return err
  153. }
  154. team := models.Team{}
  155. countSess := x.Table("team")
  156. if query.Query != "" {
  157. countSess.Where(`name `+dialect.LikeStr()+` ?`, queryWithWildcards)
  158. }
  159. if query.Name != "" {
  160. countSess.Where("name=?", query.Name)
  161. }
  162. count, err := countSess.Count(&team)
  163. query.Result.TotalCount = count
  164. return err
  165. }
  166. func GetTeamById(query *models.GetTeamByIdQuery) error {
  167. var sql bytes.Buffer
  168. sql.WriteString(getTeamSelectSqlBase())
  169. sql.WriteString(` WHERE team.org_id = ? and team.id = ?`)
  170. var team models.TeamDTO
  171. exists, err := x.SQL(sql.String(), query.OrgId, query.Id).Get(&team)
  172. if err != nil {
  173. return err
  174. }
  175. if !exists {
  176. return models.ErrTeamNotFound
  177. }
  178. query.Result = &team
  179. return nil
  180. }
  181. // GetTeamsByUser is used by the Guardian when checking a users' permissions
  182. func GetTeamsByUser(query *models.GetTeamsByUserQuery) error {
  183. query.Result = make([]*models.TeamDTO, 0)
  184. var sql bytes.Buffer
  185. sql.WriteString(getTeamSelectSqlBase())
  186. sql.WriteString(` INNER JOIN team_member on team.id = team_member.team_id`)
  187. sql.WriteString(` WHERE team.org_id = ? and team_member.user_id = ?`)
  188. err := x.SQL(sql.String(), query.OrgId, query.UserId).Find(&query.Result)
  189. return err
  190. }
  191. // AddTeamMember adds a user to a team
  192. func AddTeamMember(cmd *models.AddTeamMemberCommand) error {
  193. return inTransaction(func(sess *DBSession) error {
  194. if res, err := sess.Query("SELECT 1 from team_member WHERE org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId); err != nil {
  195. return err
  196. } else if len(res) == 1 {
  197. return models.ErrTeamMemberAlreadyAdded
  198. }
  199. if _, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  200. return err
  201. }
  202. entity := models.TeamMember{
  203. OrgId: cmd.OrgId,
  204. TeamId: cmd.TeamId,
  205. UserId: cmd.UserId,
  206. External: cmd.External,
  207. Created: time.Now(),
  208. Updated: time.Now(),
  209. Permission: cmd.Permission,
  210. }
  211. _, err := sess.Insert(&entity)
  212. return err
  213. })
  214. }
  215. func getTeamMember(sess *DBSession, orgId int64, teamId int64, userId int64) (models.TeamMember, error) {
  216. rawSql := `SELECT * FROM team_member WHERE org_id=? and team_id=? and user_id=?`
  217. var member models.TeamMember
  218. exists, err := sess.SQL(rawSql, orgId, teamId, userId).Get(&member)
  219. if err != nil {
  220. return member, err
  221. }
  222. if !exists {
  223. return member, models.ErrTeamMemberNotFound
  224. }
  225. return member, nil
  226. }
  227. // UpdateTeamMember updates a team member
  228. func UpdateTeamMember(cmd *models.UpdateTeamMemberCommand) error {
  229. return inTransaction(func(sess *DBSession) error {
  230. member, err := getTeamMember(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  231. if err != nil {
  232. return err
  233. }
  234. if cmd.ProtectLastAdmin {
  235. _, err := isLastAdmin(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  236. if err != nil {
  237. return err
  238. }
  239. }
  240. if cmd.Permission != models.PERMISSION_ADMIN { // make sure we don't get invalid permission levels in store
  241. cmd.Permission = 0
  242. }
  243. member.Permission = cmd.Permission
  244. _, err = sess.Cols("permission").Where("org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId).Update(member)
  245. return err
  246. })
  247. }
  248. // RemoveTeamMember removes a member from a team
  249. func RemoveTeamMember(cmd *models.RemoveTeamMemberCommand) error {
  250. return inTransaction(func(sess *DBSession) error {
  251. if _, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  252. return err
  253. }
  254. if cmd.ProtectLastAdmin {
  255. _, err := isLastAdmin(sess, cmd.OrgId, cmd.TeamId, cmd.UserId)
  256. if err != nil {
  257. return err
  258. }
  259. }
  260. var rawSql = "DELETE FROM team_member WHERE org_id=? and team_id=? and user_id=?"
  261. res, err := sess.Exec(rawSql, cmd.OrgId, cmd.TeamId, cmd.UserId)
  262. if err != nil {
  263. return err
  264. }
  265. rows, err := res.RowsAffected()
  266. if rows == 0 {
  267. return models.ErrTeamMemberNotFound
  268. }
  269. return err
  270. })
  271. }
  272. func isLastAdmin(sess *DBSession, orgId int64, teamId int64, userId int64) (bool, error) {
  273. rawSql := "SELECT user_id FROM team_member WHERE org_id=? and team_id=? and permission=?"
  274. userIds := []*int64{}
  275. err := sess.SQL(rawSql, orgId, teamId, models.PERMISSION_ADMIN).Find(&userIds)
  276. if err != nil {
  277. return false, err
  278. }
  279. isAdmin := false
  280. for _, adminId := range userIds {
  281. if userId == *adminId {
  282. isAdmin = true
  283. break
  284. }
  285. }
  286. if isAdmin && len(userIds) == 1 {
  287. return true, models.ErrLastTeamAdmin
  288. }
  289. return false, err
  290. }
  291. // GetTeamMembers return a list of members for the specified team
  292. func GetTeamMembers(query *models.GetTeamMembersQuery) error {
  293. query.Result = make([]*models.TeamMemberDTO, 0)
  294. sess := x.Table("team_member")
  295. sess.Join("INNER", x.Dialect().Quote("user"), fmt.Sprintf("team_member.user_id=%s.id", x.Dialect().Quote("user")))
  296. // Join with only most recent auth module
  297. authJoinCondition := `(
  298. SELECT id from user_auth
  299. WHERE user_auth.user_id = team_member.user_id
  300. ORDER BY user_auth.created DESC `
  301. authJoinCondition = "user_auth.id=" + authJoinCondition + dialect.Limit(1) + ")"
  302. sess.Join("LEFT", "user_auth", authJoinCondition)
  303. if query.OrgId != 0 {
  304. sess.Where("team_member.org_id=?", query.OrgId)
  305. }
  306. if query.TeamId != 0 {
  307. sess.Where("team_member.team_id=?", query.TeamId)
  308. }
  309. if query.UserId != 0 {
  310. sess.Where("team_member.user_id=?", query.UserId)
  311. }
  312. if query.External {
  313. sess.Where("team_member.external=?", dialect.BooleanStr(true))
  314. }
  315. sess.Cols("team_member.org_id", "team_member.team_id", "team_member.user_id", "user.email", "user.login", "team_member.external", "team_member.permission", "user_auth.auth_module")
  316. sess.Asc("user.login", "user.email")
  317. err := sess.Find(&query.Result)
  318. return err
  319. }
  320. func IsAdminOfTeams(query *models.IsAdminOfTeamsQuery) error {
  321. builder := &SqlBuilder{}
  322. builder.Write("SELECT COUNT(team.id) AS count FROM team INNER JOIN team_member ON team_member.team_id = team.id WHERE team.org_id = ? AND team_member.user_id = ? AND team_member.permission = ?", query.SignedInUser.OrgId, query.SignedInUser.UserId, models.PERMISSION_ADMIN)
  323. type teamCount struct {
  324. Count int64
  325. }
  326. resp := make([]*teamCount, 0)
  327. if err := x.SQL(builder.GetSqlString(), builder.params...).Find(&resp); err != nil {
  328. return err
  329. }
  330. query.Result = len(resp) > 0 && resp[0].Count > 0
  331. return nil
  332. }