team.go 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330
  1. package sqlstore
  2. import (
  3. "bytes"
  4. "fmt"
  5. "time"
  6. "github.com/grafana/grafana/pkg/bus"
  7. m "github.com/grafana/grafana/pkg/models"
  8. )
  9. func init() {
  10. bus.AddHandler("sql", CreateTeam)
  11. bus.AddHandler("sql", UpdateTeam)
  12. bus.AddHandler("sql", DeleteTeam)
  13. bus.AddHandler("sql", SearchTeams)
  14. bus.AddHandler("sql", GetTeamById)
  15. bus.AddHandler("sql", GetTeamsByUser)
  16. bus.AddHandler("sql", AddTeamMember)
  17. bus.AddHandler("sql", UpdateTeamMember)
  18. bus.AddHandler("sql", RemoveTeamMember)
  19. bus.AddHandler("sql", GetTeamMembers)
  20. }
  21. func getTeamSelectSqlBase() string {
  22. return `SELECT
  23. team.id as id,
  24. team.org_id,
  25. team.name as name,
  26. team.email as email,
  27. (SELECT COUNT(*) from team_member where team_member.team_id = team.id) as member_count
  28. FROM team as team `
  29. }
  30. func CreateTeam(cmd *m.CreateTeamCommand) error {
  31. return inTransaction(func(sess *DBSession) error {
  32. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, 0, sess); err != nil {
  33. return err
  34. } else if isNameTaken {
  35. return m.ErrTeamNameTaken
  36. }
  37. team := m.Team{
  38. Name: cmd.Name,
  39. Email: cmd.Email,
  40. OrgId: cmd.OrgId,
  41. Created: time.Now(),
  42. Updated: time.Now(),
  43. }
  44. _, err := sess.Insert(&team)
  45. cmd.Result = team
  46. return err
  47. })
  48. }
  49. func UpdateTeam(cmd *m.UpdateTeamCommand) error {
  50. return inTransaction(func(sess *DBSession) error {
  51. if isNameTaken, err := isTeamNameTaken(cmd.OrgId, cmd.Name, cmd.Id, sess); err != nil {
  52. return err
  53. } else if isNameTaken {
  54. return m.ErrTeamNameTaken
  55. }
  56. team := m.Team{
  57. Name: cmd.Name,
  58. Email: cmd.Email,
  59. Updated: time.Now(),
  60. }
  61. sess.MustCols("email")
  62. affectedRows, err := sess.ID(cmd.Id).Update(&team)
  63. if err != nil {
  64. return err
  65. }
  66. if affectedRows == 0 {
  67. return m.ErrTeamNotFound
  68. }
  69. return nil
  70. })
  71. }
  72. // DeleteTeam will delete a team, its member and any permissions connected to the team
  73. func DeleteTeam(cmd *m.DeleteTeamCommand) error {
  74. return inTransaction(func(sess *DBSession) error {
  75. if teamExists, err := teamExists(cmd.OrgId, cmd.Id, sess); err != nil {
  76. return err
  77. } else if !teamExists {
  78. return m.ErrTeamNotFound
  79. }
  80. deletes := []string{
  81. "DELETE FROM team_member WHERE org_id=? and team_id = ?",
  82. "DELETE FROM team WHERE org_id=? and id = ?",
  83. "DELETE FROM dashboard_acl WHERE org_id=? and team_id = ?",
  84. }
  85. for _, sql := range deletes {
  86. _, err := sess.Exec(sql, cmd.OrgId, cmd.Id)
  87. if err != nil {
  88. return err
  89. }
  90. }
  91. return nil
  92. })
  93. }
  94. func teamExists(orgId int64, teamId int64, sess *DBSession) (bool, error) {
  95. if res, err := sess.Query("SELECT 1 from team WHERE org_id=? and id=?", orgId, teamId); err != nil {
  96. return false, err
  97. } else if len(res) != 1 {
  98. return false, nil
  99. }
  100. return true, nil
  101. }
  102. func isTeamNameTaken(orgId int64, name string, existingId int64, sess *DBSession) (bool, error) {
  103. var team m.Team
  104. exists, err := sess.Where("org_id=? and name=?", orgId, name).Get(&team)
  105. if err != nil {
  106. return false, nil
  107. }
  108. if exists && existingId != team.Id {
  109. return true, nil
  110. }
  111. return false, nil
  112. }
  113. func SearchTeams(query *m.SearchTeamsQuery) error {
  114. query.Result = m.SearchTeamQueryResult{
  115. Teams: make([]*m.TeamDTO, 0),
  116. }
  117. queryWithWildcards := "%" + query.Query + "%"
  118. var sql bytes.Buffer
  119. params := make([]interface{}, 0)
  120. sql.WriteString(getTeamSelectSqlBase())
  121. if query.UserIdFilter > 0 {
  122. sql.WriteString(`INNER JOIN team_member on team.id = team_member.team_id AND team_member.user_id = ?`)
  123. params = append(params, query.UserIdFilter)
  124. }
  125. sql.WriteString(` WHERE team.org_id = ?`)
  126. params = append(params, query.OrgId)
  127. if query.Query != "" {
  128. sql.WriteString(` and team.name ` + dialect.LikeStr() + ` ?`)
  129. params = append(params, queryWithWildcards)
  130. }
  131. if query.Name != "" {
  132. sql.WriteString(` and team.name = ?`)
  133. params = append(params, query.Name)
  134. }
  135. sql.WriteString(` order by team.name asc`)
  136. if query.Limit != 0 {
  137. offset := query.Limit * (query.Page - 1)
  138. sql.WriteString(dialect.LimitOffset(int64(query.Limit), int64(offset)))
  139. }
  140. if err := x.SQL(sql.String(), params...).Find(&query.Result.Teams); err != nil {
  141. return err
  142. }
  143. team := m.Team{}
  144. countSess := x.Table("team")
  145. if query.Query != "" {
  146. countSess.Where(`name `+dialect.LikeStr()+` ?`, queryWithWildcards)
  147. }
  148. if query.Name != "" {
  149. countSess.Where("name=?", query.Name)
  150. }
  151. count, err := countSess.Count(&team)
  152. query.Result.TotalCount = count
  153. return err
  154. }
  155. func GetTeamById(query *m.GetTeamByIdQuery) error {
  156. var sql bytes.Buffer
  157. sql.WriteString(getTeamSelectSqlBase())
  158. sql.WriteString(` WHERE team.org_id = ? and team.id = ?`)
  159. var team m.TeamDTO
  160. exists, err := x.SQL(sql.String(), query.OrgId, query.Id).Get(&team)
  161. if err != nil {
  162. return err
  163. }
  164. if !exists {
  165. return m.ErrTeamNotFound
  166. }
  167. query.Result = &team
  168. return nil
  169. }
  170. // GetTeamsByUser is used by the Guardian when checking a users' permissions
  171. func GetTeamsByUser(query *m.GetTeamsByUserQuery) error {
  172. query.Result = make([]*m.TeamDTO, 0)
  173. var sql bytes.Buffer
  174. sql.WriteString(getTeamSelectSqlBase())
  175. sql.WriteString(` INNER JOIN team_member on team.id = team_member.team_id`)
  176. sql.WriteString(` WHERE team.org_id = ? and team_member.user_id = ?`)
  177. err := x.SQL(sql.String(), query.OrgId, query.UserId).Find(&query.Result)
  178. return err
  179. }
  180. // AddTeamMember adds a user to a team
  181. func AddTeamMember(cmd *m.AddTeamMemberCommand) error {
  182. return inTransaction(func(sess *DBSession) error {
  183. if res, err := sess.Query("SELECT 1 from team_member WHERE org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId); err != nil {
  184. return err
  185. } else if len(res) == 1 {
  186. return m.ErrTeamMemberAlreadyAdded
  187. }
  188. if teamExists, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  189. return err
  190. } else if !teamExists {
  191. return m.ErrTeamNotFound
  192. }
  193. entity := m.TeamMember{
  194. OrgId: cmd.OrgId,
  195. TeamId: cmd.TeamId,
  196. UserId: cmd.UserId,
  197. External: cmd.External,
  198. Created: time.Now(),
  199. Updated: time.Now(),
  200. Permission: cmd.Permission,
  201. }
  202. _, err := sess.Insert(&entity)
  203. return err
  204. })
  205. }
  206. // UpdateTeamMember updates a team member
  207. func UpdateTeamMember(cmd *m.UpdateTeamMemberCommand) error {
  208. return inTransaction(func(sess *DBSession) error {
  209. rawSql := `SELECT * FROM team_member WHERE org_id=? and team_id=? and user_id=?`
  210. var member m.TeamMember
  211. exists, err := sess.SQL(rawSql, cmd.OrgId, cmd.TeamId, cmd.UserId).Get(&member)
  212. if err != nil {
  213. return err
  214. }
  215. if !exists {
  216. return m.ErrTeamMemberNotFound
  217. }
  218. member.Permission = cmd.Permission
  219. _, err = sess.Cols("permission").Where("org_id=? and team_id=? and user_id=?", cmd.OrgId, cmd.TeamId, cmd.UserId).Update(member)
  220. return err
  221. })
  222. }
  223. // RemoveTeamMember removes a member from a team
  224. func RemoveTeamMember(cmd *m.RemoveTeamMemberCommand) error {
  225. return inTransaction(func(sess *DBSession) error {
  226. if teamExists, err := teamExists(cmd.OrgId, cmd.TeamId, sess); err != nil {
  227. return err
  228. } else if !teamExists {
  229. return m.ErrTeamNotFound
  230. }
  231. var rawSql = "DELETE FROM team_member WHERE org_id=? and team_id=? and user_id=?"
  232. res, err := sess.Exec(rawSql, cmd.OrgId, cmd.TeamId, cmd.UserId)
  233. if err != nil {
  234. return err
  235. }
  236. rows, err := res.RowsAffected()
  237. if rows == 0 {
  238. return m.ErrTeamMemberNotFound
  239. }
  240. return err
  241. })
  242. }
  243. // GetTeamMembers return a list of members for the specified team
  244. func GetTeamMembers(query *m.GetTeamMembersQuery) error {
  245. query.Result = make([]*m.TeamMemberDTO, 0)
  246. sess := x.Table("team_member")
  247. sess.Join("INNER", x.Dialect().Quote("user"), fmt.Sprintf("team_member.user_id=%s.id", x.Dialect().Quote("user")))
  248. if query.OrgId != 0 {
  249. sess.Where("team_member.org_id=?", query.OrgId)
  250. }
  251. if query.TeamId != 0 {
  252. sess.Where("team_member.team_id=?", query.TeamId)
  253. }
  254. if query.UserId != 0 {
  255. sess.Where("team_member.user_id=?", query.UserId)
  256. }
  257. if query.External {
  258. sess.Where("team_member.external=?", dialect.BooleanStr(true))
  259. }
  260. sess.Cols("team_member.org_id", "team_member.team_id", "team_member.user_id", "user.email", "user.login", "team_member.external", "team_member.permission")
  261. sess.Asc("user.login", "user.email")
  262. err := sess.Find(&query.Result)
  263. return err
  264. }