dashboard.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  22. bus.AddHandler("sql", GetDashboardsBySlug)
  23. bus.AddHandler("sql", ValidateDashboardBeforeSave)
  24. }
  25. var generateNewUid func() string = util.GenerateShortUid
  26. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  27. return inTransaction(func(sess *DBSession) error {
  28. return saveDashboard(sess, cmd)
  29. })
  30. }
  31. func saveDashboard(sess *DBSession, cmd *m.SaveDashboardCommand) error {
  32. dash := cmd.GetDashboardModel()
  33. userId := cmd.UserId
  34. if userId == 0 {
  35. userId = -1
  36. }
  37. if dash.Id > 0 {
  38. var existing m.Dashboard
  39. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  40. if err != nil {
  41. return err
  42. }
  43. if !dashWithIdExists {
  44. return m.ErrDashboardNotFound
  45. }
  46. // check for is someone else has written in between
  47. if dash.Version != existing.Version {
  48. if cmd.Overwrite {
  49. dash.SetVersion(existing.Version)
  50. } else {
  51. return m.ErrDashboardVersionMismatch
  52. }
  53. }
  54. // do not allow plugin dashboard updates without overwrite flag
  55. if existing.PluginId != "" && cmd.Overwrite == false {
  56. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  57. }
  58. }
  59. if dash.Uid == "" {
  60. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  61. if err != nil {
  62. return err
  63. }
  64. dash.SetUid(uid)
  65. }
  66. parentVersion := dash.Version
  67. affectedRows := int64(0)
  68. var err error
  69. if dash.Id == 0 {
  70. dash.SetVersion(1)
  71. dash.Created = time.Now()
  72. dash.CreatedBy = userId
  73. dash.Updated = time.Now()
  74. dash.UpdatedBy = userId
  75. metrics.M_Api_Dashboard_Insert.Inc()
  76. affectedRows, err = sess.Insert(dash)
  77. } else {
  78. dash.SetVersion(dash.Version + 1)
  79. if !cmd.UpdatedAt.IsZero() {
  80. dash.Updated = cmd.UpdatedAt
  81. } else {
  82. dash.Updated = time.Now()
  83. }
  84. dash.UpdatedBy = userId
  85. affectedRows, err = sess.MustCols("folder_id").ID(dash.Id).Update(dash)
  86. }
  87. if err != nil {
  88. return err
  89. }
  90. if affectedRows == 0 {
  91. return m.ErrDashboardNotFound
  92. }
  93. dashVersion := &m.DashboardVersion{
  94. DashboardId: dash.Id,
  95. ParentVersion: parentVersion,
  96. RestoredFrom: cmd.RestoredFrom,
  97. Version: dash.Version,
  98. Created: time.Now(),
  99. CreatedBy: dash.UpdatedBy,
  100. Message: cmd.Message,
  101. Data: dash.Data,
  102. }
  103. // insert version entry
  104. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  105. return err
  106. } else if affectedRows == 0 {
  107. return m.ErrDashboardNotFound
  108. }
  109. // delete existing tags
  110. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  111. if err != nil {
  112. return err
  113. }
  114. // insert new tags
  115. tags := dash.GetTags()
  116. if len(tags) > 0 {
  117. for _, tag := range tags {
  118. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  119. return err
  120. }
  121. }
  122. }
  123. cmd.Result = dash
  124. return err
  125. }
  126. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  127. for i := 0; i < 3; i++ {
  128. uid := generateNewUid()
  129. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&m.Dashboard{})
  130. if err != nil {
  131. return "", err
  132. }
  133. if !exists {
  134. return uid, nil
  135. }
  136. }
  137. return "", m.ErrDashboardFailedGenerateUniqueUid
  138. }
  139. func GetDashboard(query *m.GetDashboardQuery) error {
  140. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  141. has, err := x.Get(&dashboard)
  142. if err != nil {
  143. return err
  144. } else if has == false {
  145. return m.ErrDashboardNotFound
  146. }
  147. dashboard.SetId(dashboard.Id)
  148. dashboard.SetUid(dashboard.Uid)
  149. query.Result = &dashboard
  150. return nil
  151. }
  152. type DashboardSearchProjection struct {
  153. Id int64
  154. Uid string
  155. Title string
  156. Slug string
  157. Term string
  158. IsFolder bool
  159. FolderId int64
  160. FolderUid string
  161. FolderSlug string
  162. FolderTitle string
  163. }
  164. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  165. limit := query.Limit
  166. if limit == 0 {
  167. limit = 1000
  168. }
  169. sb := NewSearchBuilder(query.SignedInUser, limit, query.Permission).
  170. WithTags(query.Tags).
  171. WithDashboardIdsIn(query.DashboardIds)
  172. if query.IsStarred {
  173. sb.IsStarred()
  174. }
  175. if len(query.Title) > 0 {
  176. sb.WithTitle(query.Title)
  177. }
  178. if len(query.Type) > 0 {
  179. sb.WithType(query.Type)
  180. }
  181. if len(query.FolderIds) > 0 {
  182. sb.WithFolderIds(query.FolderIds)
  183. }
  184. var res []DashboardSearchProjection
  185. sql, params := sb.ToSql()
  186. err := x.Sql(sql, params...).Find(&res)
  187. if err != nil {
  188. return nil, err
  189. }
  190. return res, nil
  191. }
  192. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  193. res, err := findDashboards(query)
  194. if err != nil {
  195. return err
  196. }
  197. makeQueryResult(query, res)
  198. return nil
  199. }
  200. func getHitType(item DashboardSearchProjection) search.HitType {
  201. var hitType search.HitType
  202. if item.IsFolder {
  203. hitType = search.DashHitFolder
  204. } else {
  205. hitType = search.DashHitDB
  206. }
  207. return hitType
  208. }
  209. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  210. query.Result = make([]*search.Hit, 0)
  211. hits := make(map[int64]*search.Hit)
  212. for _, item := range res {
  213. hit, exists := hits[item.Id]
  214. if !exists {
  215. hit = &search.Hit{
  216. Id: item.Id,
  217. Uid: item.Uid,
  218. Title: item.Title,
  219. Uri: "db/" + item.Slug,
  220. Url: m.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  221. Type: getHitType(item),
  222. FolderId: item.FolderId,
  223. FolderUid: item.FolderUid,
  224. FolderTitle: item.FolderTitle,
  225. Tags: []string{},
  226. }
  227. if item.FolderId > 0 {
  228. hit.FolderUrl = m.GetFolderUrl(item.FolderUid, item.FolderSlug)
  229. }
  230. query.Result = append(query.Result, hit)
  231. hits[item.Id] = hit
  232. }
  233. if len(item.Term) > 0 {
  234. hit.Tags = append(hit.Tags, item.Term)
  235. }
  236. }
  237. }
  238. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  239. sql := `SELECT
  240. COUNT(*) as count,
  241. term
  242. FROM dashboard
  243. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  244. WHERE dashboard.org_id=?
  245. GROUP BY term`
  246. query.Result = make([]*m.DashboardTagCloudItem, 0)
  247. sess := x.Sql(sql, query.OrgId)
  248. err := sess.Find(&query.Result)
  249. return err
  250. }
  251. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  252. return inTransaction(func(sess *DBSession) error {
  253. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  254. has, err := sess.Get(&dashboard)
  255. if err != nil {
  256. return err
  257. } else if has == false {
  258. return m.ErrDashboardNotFound
  259. }
  260. deletes := []string{
  261. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  262. "DELETE FROM star WHERE dashboard_id = ? ",
  263. "DELETE FROM dashboard WHERE id = ?",
  264. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  265. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  266. "DELETE FROM dashboard WHERE folder_id = ?",
  267. "DELETE FROM annotation WHERE dashboard_id = ?",
  268. "DELETE FROM dashboard_provisioning WHERE dashboard_id = ?",
  269. }
  270. for _, sql := range deletes {
  271. _, err := sess.Exec(sql, dashboard.Id)
  272. if err != nil {
  273. return err
  274. }
  275. }
  276. if err := deleteAlertDefinition(dashboard.Id, sess); err != nil {
  277. return nil
  278. }
  279. return nil
  280. })
  281. }
  282. func GetDashboards(query *m.GetDashboardsQuery) error {
  283. if len(query.DashboardIds) == 0 {
  284. return m.ErrCommandValidationFailed
  285. }
  286. var dashboards = make([]*m.Dashboard, 0)
  287. err := x.In("id", query.DashboardIds).Find(&dashboards)
  288. query.Result = dashboards
  289. return err
  290. }
  291. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  292. // The function takes in a list of dashboard ids and the user id and role
  293. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  294. if len(query.DashboardIds) == 0 {
  295. return m.ErrCommandValidationFailed
  296. }
  297. if query.OrgRole == m.ROLE_ADMIN {
  298. var permissions = make([]*m.DashboardPermissionForUser, 0)
  299. for _, d := range query.DashboardIds {
  300. permissions = append(permissions, &m.DashboardPermissionForUser{
  301. DashboardId: d,
  302. Permission: m.PERMISSION_ADMIN,
  303. PermissionName: m.PERMISSION_ADMIN.String(),
  304. })
  305. }
  306. query.Result = permissions
  307. return nil
  308. }
  309. params := make([]interface{}, 0)
  310. // check dashboards that have ACLs via user id, team id or role
  311. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  312. FROM dashboard AS d
  313. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  314. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  315. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  316. `
  317. params = append(params, query.UserId)
  318. //check the user's role for dashboards that do not have hasAcl set
  319. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  320. params = append(params, query.UserId)
  321. params = append(params, query.OrgId)
  322. sql += `
  323. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  324. UNION SELECT 2 AS permission, 'Editor' AS role
  325. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  326. WHERE
  327. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  328. for _, id := range query.DashboardIds {
  329. params = append(params, id)
  330. }
  331. sql += ` AND
  332. d.org_id = ? AND
  333. (
  334. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  335. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  336. )
  337. group by d.id
  338. order by d.id asc`
  339. params = append(params, query.OrgId)
  340. params = append(params, dialect.BooleanStr(true))
  341. params = append(params, query.UserId)
  342. params = append(params, query.UserId)
  343. params = append(params, dialect.BooleanStr(false))
  344. err := x.Sql(sql, params...).Find(&query.Result)
  345. for _, p := range query.Result {
  346. p.PermissionName = p.Permission.String()
  347. }
  348. return err
  349. }
  350. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  351. var dashboards = make([]*m.Dashboard, 0)
  352. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  353. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  354. query.Result = dashboards
  355. return err
  356. }
  357. type DashboardSlugDTO struct {
  358. Slug string
  359. }
  360. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  361. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  362. var slug = DashboardSlugDTO{}
  363. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  364. if err != nil {
  365. return err
  366. } else if exists == false {
  367. return m.ErrDashboardNotFound
  368. }
  369. query.Result = slug.Slug
  370. return nil
  371. }
  372. func GetDashboardsBySlug(query *m.GetDashboardsBySlugQuery) error {
  373. var dashboards []*m.Dashboard
  374. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  375. return err
  376. }
  377. query.Result = dashboards
  378. return nil
  379. }
  380. func GetDashboardUIDById(query *m.GetDashboardRefByIdQuery) error {
  381. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  382. us := &m.DashboardRef{}
  383. exists, err := x.SQL(rawSql, query.Id).Get(us)
  384. if err != nil {
  385. return err
  386. } else if exists == false {
  387. return m.ErrDashboardNotFound
  388. }
  389. query.Result = us
  390. return nil
  391. }
  392. func getExistingDashboardByIdOrUidForUpdate(sess *DBSession, cmd *m.ValidateDashboardBeforeSaveCommand) (err error) {
  393. dash := cmd.Dashboard
  394. dashWithIdExists := false
  395. var existingById m.Dashboard
  396. if dash.Id > 0 {
  397. dashWithIdExists, err = sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existingById)
  398. if err != nil {
  399. return err
  400. }
  401. if !dashWithIdExists {
  402. return m.ErrDashboardNotFound
  403. }
  404. if dash.Uid == "" {
  405. dash.SetUid(existingById.Uid)
  406. }
  407. }
  408. dashWithUidExists := false
  409. var existingByUid m.Dashboard
  410. if dash.Uid != "" {
  411. dashWithUidExists, err = sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&existingByUid)
  412. if err != nil {
  413. return err
  414. }
  415. }
  416. if dash.FolderId > 0 {
  417. var existingFolder m.Dashboard
  418. folderExists, folderErr := sess.Where("org_id=? AND id=? AND is_folder=?", dash.OrgId, dash.FolderId, dialect.BooleanStr(true)).Get(&existingFolder)
  419. if folderErr != nil {
  420. return folderErr
  421. }
  422. if !folderExists {
  423. return m.ErrDashboardFolderNotFound
  424. }
  425. }
  426. if !dashWithIdExists && !dashWithUidExists {
  427. return nil
  428. }
  429. if dashWithIdExists && dashWithUidExists && existingById.Id != existingByUid.Id {
  430. return m.ErrDashboardWithSameUIDExists
  431. }
  432. existing := existingById
  433. if !dashWithIdExists && dashWithUidExists {
  434. dash.SetId(existingByUid.Id)
  435. dash.SetUid(existingByUid.Uid)
  436. existing = existingByUid
  437. }
  438. if (existing.IsFolder && !dash.IsFolder) ||
  439. (!existing.IsFolder && dash.IsFolder) {
  440. return m.ErrDashboardTypeMismatch
  441. }
  442. // check for is someone else has written in between
  443. if dash.Version != existing.Version {
  444. if cmd.Overwrite {
  445. dash.SetVersion(existing.Version)
  446. } else {
  447. return m.ErrDashboardVersionMismatch
  448. }
  449. }
  450. // do not allow plugin dashboard updates without overwrite flag
  451. if existing.PluginId != "" && cmd.Overwrite == false {
  452. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  453. }
  454. return nil
  455. }
  456. func getExistingDashboardByTitleAndFolder(sess *DBSession, cmd *m.ValidateDashboardBeforeSaveCommand) error {
  457. dash := cmd.Dashboard
  458. var existing m.Dashboard
  459. exists, err := sess.Where("org_id=? AND slug=? AND (is_folder=? OR folder_id=?)", dash.OrgId, dash.Slug, dialect.BooleanStr(true), dash.FolderId).Get(&existing)
  460. if err != nil {
  461. return err
  462. }
  463. if exists && dash.Id != existing.Id {
  464. if existing.IsFolder && !dash.IsFolder {
  465. return m.ErrDashboardWithSameNameAsFolder
  466. }
  467. if !existing.IsFolder && dash.IsFolder {
  468. return m.ErrDashboardFolderWithSameNameAsDashboard
  469. }
  470. if cmd.Overwrite {
  471. dash.SetId(existing.Id)
  472. dash.SetUid(existing.Uid)
  473. dash.SetVersion(existing.Version)
  474. } else {
  475. return m.ErrDashboardWithSameNameInFolderExists
  476. }
  477. }
  478. return nil
  479. }
  480. func ValidateDashboardBeforeSave(cmd *m.ValidateDashboardBeforeSaveCommand) (err error) {
  481. return inTransaction(func(sess *DBSession) error {
  482. if err = getExistingDashboardByIdOrUidForUpdate(sess, cmd); err != nil {
  483. return err
  484. }
  485. if err = getExistingDashboardByTitleAndFolder(sess, cmd); err != nil {
  486. return err
  487. }
  488. return nil
  489. })
  490. }