| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366 |
- package sqlstore
- import (
- "testing"
- "github.com/go-xorm/xorm"
- . "github.com/smartystreets/goconvey/convey"
- m "github.com/grafana/grafana/pkg/models"
- "github.com/grafana/grafana/pkg/services/search"
- )
- func TestDashboardFolderDataAccess(t *testing.T) {
- var x *xorm.Engine
- Convey("Testing DB", t, func() {
- x = InitTestDB(t)
- Convey("Given one dashboard folder with two dashboards and one dashboard in the root folder", func() {
- folder := insertTestDashboard("1 test dash folder", 1, 0, true, "prod", "webapp")
- dashInRoot := insertTestDashboard("test dash 67", 1, 0, false, "prod", "webapp")
- childDash := insertTestDashboard("test dash 23", 1, folder.Id, false, "prod", "webapp")
- insertTestDashboard("test dash 45", 1, folder.Id, false, "prod")
- currentUser := createUser("viewer", "Viewer", false)
- Convey("and no acls are set", func() {
- Convey("should return all dashboards", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1,
- DashboardIds: []int64{folder.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, folder.Id)
- So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("and acl is set for dashboard folder", func() {
- var otherUser int64 = 999
- updateTestDashboardWithAcl(folder.Id, otherUser, m.PERMISSION_EDIT)
- Convey("should not return folder", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1, DashboardIds: []int64{folder.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 1)
- So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
- })
- Convey("when the user is given permission", func() {
- updateTestDashboardWithAcl(folder.Id, currentUser.Id, m.PERMISSION_EDIT)
- Convey("should be able to access folder", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1,
- DashboardIds: []int64{folder.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, folder.Id)
- So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("when the user is an admin", func() {
- Convey("should be able to access folder", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{
- UserId: currentUser.Id,
- OrgId: 1,
- OrgRole: m.ROLE_ADMIN,
- },
- OrgId: 1,
- DashboardIds: []int64{folder.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, folder.Id)
- So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- })
- Convey("and acl is set for dashboard child and folder has all permissions removed", func() {
- var otherUser int64 = 999
- aclId := updateTestDashboardWithAcl(folder.Id, otherUser, m.PERMISSION_EDIT)
- removeAcl(aclId)
- updateTestDashboardWithAcl(childDash.Id, otherUser, m.PERMISSION_EDIT)
- Convey("should not return folder or child", func() {
- query := &search.FindPersistedDashboardsQuery{SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1, DashboardIds: []int64{folder.Id, childDash.Id, dashInRoot.Id}}
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 1)
- So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
- })
- Convey("when the user is given permission to child", func() {
- updateTestDashboardWithAcl(childDash.Id, currentUser.Id, m.PERMISSION_EDIT)
- Convey("should be able to search for child dashboard but not folder", func() {
- query := &search.FindPersistedDashboardsQuery{SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1, DashboardIds: []int64{folder.Id, childDash.Id, dashInRoot.Id}}
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, childDash.Id)
- So(query.Result[1].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("when the user is an admin", func() {
- Convey("should be able to search for child dash and folder", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{
- UserId: currentUser.Id,
- OrgId: 1,
- OrgRole: m.ROLE_ADMIN,
- },
- OrgId: 1,
- DashboardIds: []int64{folder.Id, dashInRoot.Id, childDash.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 3)
- So(query.Result[0].Id, ShouldEqual, folder.Id)
- So(query.Result[1].Id, ShouldEqual, childDash.Id)
- So(query.Result[2].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- })
- })
- Convey("Given two dashboard folders with one dashboard each and one dashboard in the root folder", func() {
- folder1 := insertTestDashboard("1 test dash folder", 1, 0, true, "prod")
- folder2 := insertTestDashboard("2 test dash folder", 1, 0, true, "prod")
- dashInRoot := insertTestDashboard("test dash 67", 1, 0, false, "prod")
- childDash1 := insertTestDashboard("child dash 1", 1, folder1.Id, false, "prod")
- childDash2 := insertTestDashboard("child dash 2", 1, folder2.Id, false, "prod")
- currentUser := createUser("viewer", "Viewer", false)
- var rootFolderId int64 = 0
- Convey("and one folder is expanded, the other collapsed", func() {
- Convey("should return dashboards in root and expanded folder", func() {
- query := &search.FindPersistedDashboardsQuery{FolderIds: []int64{rootFolderId, folder1.Id}, SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER}, OrgId: 1}
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 4)
- So(query.Result[0].Id, ShouldEqual, folder1.Id)
- So(query.Result[1].Id, ShouldEqual, folder2.Id)
- So(query.Result[2].Id, ShouldEqual, childDash1.Id)
- So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("and acl is set for one dashboard folder", func() {
- var otherUser int64 = 999
- updateTestDashboardWithAcl(folder1.Id, otherUser, m.PERMISSION_EDIT)
- Convey("and a dashboard is moved from folder without acl to the folder with an acl", func() {
- movedDash := moveDashboard(1, childDash2.Data, folder1.Id)
- So(movedDash.HasAcl, ShouldBeTrue)
- Convey("should not return folder with acl or its children", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1,
- DashboardIds: []int64{folder1.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 1)
- So(query.Result[0].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("and a dashboard is moved from folder with acl to the folder without an acl", func() {
- movedDash := moveDashboard(1, childDash1.Data, folder2.Id)
- So(movedDash.HasAcl, ShouldBeFalse)
- Convey("should return folder without acl and its children", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1,
- DashboardIds: []int64{folder2.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 4)
- So(query.Result[0].Id, ShouldEqual, folder2.Id)
- So(query.Result[1].Id, ShouldEqual, childDash1.Id)
- So(query.Result[2].Id, ShouldEqual, childDash2.Id)
- So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- Convey("and a dashboard with an acl is moved to the folder without an acl", func() {
- updateTestDashboardWithAcl(childDash1.Id, otherUser, m.PERMISSION_EDIT)
- movedDash := moveDashboard(1, childDash1.Data, folder2.Id)
- So(movedDash.HasAcl, ShouldBeTrue)
- Convey("should return folder without acl but not the dashboard with acl", func() {
- query := &search.FindPersistedDashboardsQuery{
- SignedInUser: &m.SignedInUser{UserId: currentUser.Id, OrgId: 1, OrgRole: m.ROLE_VIEWER},
- OrgId: 1,
- DashboardIds: []int64{folder2.Id, childDash1.Id, childDash2.Id, dashInRoot.Id},
- }
- err := SearchDashboards(query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 4)
- So(query.Result[0].Id, ShouldEqual, folder2.Id)
- So(query.Result[1].Id, ShouldEqual, childDash1.Id)
- So(query.Result[2].Id, ShouldEqual, childDash2.Id)
- So(query.Result[3].Id, ShouldEqual, dashInRoot.Id)
- })
- })
- })
- })
- Convey("Given two dashboard folders", func() {
- folder1 := insertTestDashboard("1 test dash folder", 1, 0, true, "prod")
- folder2 := insertTestDashboard("2 test dash folder", 1, 0, true, "prod")
- insertTestDashboard("folder in another org", 2, 0, true, "prod")
- adminUser := createUser("admin", "Admin", true)
- editorUser := createUser("editor", "Editor", false)
- viewerUser := createUser("viewer", "Viewer", false)
- Convey("Admin users", func() {
- Convey("Should have write access to all dashboard folders in their org", func() {
- query := search.FindPersistedDashboardsQuery{
- OrgId: 1,
- SignedInUser: &m.SignedInUser{UserId: adminUser.Id, OrgRole: m.ROLE_ADMIN, OrgId: 1},
- Permission: m.PERMISSION_VIEW,
- Type: "dash-folder",
- }
- err := SearchDashboards(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, folder1.Id)
- So(query.Result[1].Id, ShouldEqual, folder2.Id)
- })
- Convey("should have write access to all folders and dashboards", func() {
- query := m.GetDashboardPermissionsForUserQuery{
- DashboardIds: []int64{folder1.Id, folder2.Id},
- OrgId: 1,
- UserId: adminUser.Id,
- OrgRole: m.ROLE_ADMIN,
- }
- err := GetDashboardPermissionsForUser(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
- So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_ADMIN)
- So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
- So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_ADMIN)
- })
- })
- Convey("Editor users", func() {
- query := search.FindPersistedDashboardsQuery{
- OrgId: 1,
- SignedInUser: &m.SignedInUser{UserId: editorUser.Id, OrgRole: m.ROLE_EDITOR, OrgId: 1},
- Permission: m.PERMISSION_EDIT,
- }
- Convey("Should have write access to all dashboard folders with default ACL", func() {
- err := SearchDashboards(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].Id, ShouldEqual, folder1.Id)
- So(query.Result[1].Id, ShouldEqual, folder2.Id)
- })
- Convey("should have edit access to folders with default ACL", func() {
- query := m.GetDashboardPermissionsForUserQuery{
- DashboardIds: []int64{folder1.Id, folder2.Id},
- OrgId: 1,
- UserId: editorUser.Id,
- OrgRole: m.ROLE_EDITOR,
- }
- err := GetDashboardPermissionsForUser(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
- So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_EDIT)
- So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
- So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_EDIT)
- })
- Convey("Should have write access to one dashboard folder if default role changed to view for one folder", func() {
- updateTestDashboardWithAcl(folder1.Id, editorUser.Id, m.PERMISSION_VIEW)
- err := SearchDashboards(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 1)
- So(query.Result[0].Id, ShouldEqual, folder2.Id)
- })
- })
- Convey("Viewer users", func() {
- query := search.FindPersistedDashboardsQuery{
- OrgId: 1,
- SignedInUser: &m.SignedInUser{UserId: viewerUser.Id, OrgRole: m.ROLE_VIEWER, OrgId: 1},
- Permission: m.PERMISSION_EDIT,
- }
- Convey("Should have no write access to any dashboard folders with default ACL", func() {
- err := SearchDashboards(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 0)
- })
- Convey("should have view access to folders with default ACL", func() {
- query := m.GetDashboardPermissionsForUserQuery{
- DashboardIds: []int64{folder1.Id, folder2.Id},
- OrgId: 1,
- UserId: viewerUser.Id,
- OrgRole: m.ROLE_VIEWER,
- }
- err := GetDashboardPermissionsForUser(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 2)
- So(query.Result[0].DashboardId, ShouldEqual, folder1.Id)
- So(query.Result[0].Permission, ShouldEqual, m.PERMISSION_VIEW)
- So(query.Result[1].DashboardId, ShouldEqual, folder2.Id)
- So(query.Result[1].Permission, ShouldEqual, m.PERMISSION_VIEW)
- })
- Convey("Should be able to get one dashboard folder if default role changed to edit for one folder", func() {
- updateTestDashboardWithAcl(folder1.Id, viewerUser.Id, m.PERMISSION_EDIT)
- err := SearchDashboards(&query)
- So(err, ShouldBeNil)
- So(len(query.Result), ShouldEqual, 1)
- So(query.Result[0].Id, ShouldEqual, folder1.Id)
- })
- })
- })
- })
- }
|