dashboard.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. func init() {
  12. bus.AddHandler("sql", SaveDashboard)
  13. bus.AddHandler("sql", GetDashboard)
  14. bus.AddHandler("sql", GetDashboards)
  15. bus.AddHandler("sql", DeleteDashboard)
  16. bus.AddHandler("sql", SearchDashboards)
  17. bus.AddHandler("sql", GetDashboardTags)
  18. bus.AddHandler("sql", GetDashboardSlugById)
  19. bus.AddHandler("sql", GetDashboardUIDById)
  20. bus.AddHandler("sql", GetDashboardsByPluginId)
  21. bus.AddHandler("sql", GetFoldersForSignedInUser)
  22. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  23. bus.AddHandler("sql", GetDashboardsBySlug)
  24. }
  25. var generateNewUid func() string = util.GenerateShortUid
  26. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  27. return inTransaction(func(sess *DBSession) error {
  28. return saveDashboard(sess, cmd)
  29. })
  30. }
  31. func saveDashboard(sess *DBSession, cmd *m.SaveDashboardCommand) error {
  32. dash := cmd.GetDashboardModel()
  33. if err := getExistingDashboardForUpdate(sess, dash, cmd); err != nil {
  34. return err
  35. }
  36. var existingByTitleAndFolder m.Dashboard
  37. dashWithTitleAndFolderExists, err := sess.Where("org_id=? AND slug=? AND (is_folder=? OR folder_id=?)", dash.OrgId, dash.Slug, dialect.BooleanStr(true), dash.FolderId).Get(&existingByTitleAndFolder)
  38. if err != nil {
  39. return err
  40. }
  41. if dashWithTitleAndFolderExists {
  42. if dash.Id != existingByTitleAndFolder.Id {
  43. if existingByTitleAndFolder.IsFolder && !cmd.IsFolder {
  44. return m.ErrDashboardWithSameNameAsFolder
  45. }
  46. if !existingByTitleAndFolder.IsFolder && cmd.IsFolder {
  47. return m.ErrDashboardFolderWithSameNameAsDashboard
  48. }
  49. if cmd.Overwrite {
  50. dash.Id = existingByTitleAndFolder.Id
  51. dash.Version = existingByTitleAndFolder.Version
  52. if dash.Uid == "" {
  53. dash.Uid = existingByTitleAndFolder.Uid
  54. }
  55. } else {
  56. return m.ErrDashboardWithSameNameInFolderExists
  57. }
  58. }
  59. }
  60. if dash.Uid == "" {
  61. uid, err := generateNewDashboardUid(sess, dash.OrgId)
  62. if err != nil {
  63. return err
  64. }
  65. dash.Uid = uid
  66. dash.Data.Set("uid", uid)
  67. }
  68. err = setHasAcl(sess, dash)
  69. if err != nil {
  70. return err
  71. }
  72. parentVersion := dash.Version
  73. affectedRows := int64(0)
  74. if dash.Id == 0 {
  75. dash.Version = 1
  76. metrics.M_Api_Dashboard_Insert.Inc()
  77. dash.Data.Set("version", dash.Version)
  78. affectedRows, err = sess.Insert(dash)
  79. } else {
  80. dash.Version++
  81. dash.Data.Set("version", dash.Version)
  82. if !cmd.UpdatedAt.IsZero() {
  83. dash.Updated = cmd.UpdatedAt
  84. }
  85. affectedRows, err = sess.MustCols("folder_id", "has_acl").ID(dash.Id).Update(dash)
  86. }
  87. if err != nil {
  88. return err
  89. }
  90. if affectedRows == 0 {
  91. return m.ErrDashboardNotFound
  92. }
  93. dashVersion := &m.DashboardVersion{
  94. DashboardId: dash.Id,
  95. ParentVersion: parentVersion,
  96. RestoredFrom: cmd.RestoredFrom,
  97. Version: dash.Version,
  98. Created: time.Now(),
  99. CreatedBy: dash.UpdatedBy,
  100. Message: cmd.Message,
  101. Data: dash.Data,
  102. }
  103. // insert version entry
  104. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  105. return err
  106. } else if affectedRows == 0 {
  107. return m.ErrDashboardNotFound
  108. }
  109. // delete existing tags
  110. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  111. if err != nil {
  112. return err
  113. }
  114. // insert new tags
  115. tags := dash.GetTags()
  116. if len(tags) > 0 {
  117. for _, tag := range tags {
  118. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  119. return err
  120. }
  121. }
  122. }
  123. cmd.Result = dash
  124. return err
  125. }
  126. func getExistingDashboardForUpdate(sess *DBSession, dash *m.Dashboard, cmd *m.SaveDashboardCommand) (err error) {
  127. dashWithIdExists := false
  128. var existingById m.Dashboard
  129. if dash.Id > 0 {
  130. dashWithIdExists, err = sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existingById)
  131. if err != nil {
  132. return err
  133. }
  134. if !dashWithIdExists {
  135. return m.ErrDashboardNotFound
  136. }
  137. if dash.Uid == "" {
  138. dash.Uid = existingById.Uid
  139. }
  140. }
  141. dashWithUidExists := false
  142. var existingByUid m.Dashboard
  143. if dash.Uid != "" {
  144. dashWithUidExists, err = sess.Where("org_id=? AND uid=?", dash.OrgId, dash.Uid).Get(&existingByUid)
  145. if err != nil {
  146. return err
  147. }
  148. }
  149. if !dashWithIdExists && !dashWithUidExists {
  150. return nil
  151. }
  152. if dashWithIdExists && dashWithUidExists && existingById.Id != existingByUid.Id {
  153. return m.ErrDashboardWithSameUIDExists
  154. }
  155. existing := existingById
  156. if !dashWithIdExists && dashWithUidExists {
  157. dash.Id = existingByUid.Id
  158. existing = existingByUid
  159. }
  160. if (existing.IsFolder && !cmd.IsFolder) ||
  161. (!existing.IsFolder && cmd.IsFolder) {
  162. return m.ErrDashboardTypeMismatch
  163. }
  164. // check for is someone else has written in between
  165. if dash.Version != existing.Version {
  166. if cmd.Overwrite {
  167. dash.Version = existing.Version
  168. } else {
  169. return m.ErrDashboardVersionMismatch
  170. }
  171. }
  172. // do not allow plugin dashboard updates without overwrite flag
  173. if existing.PluginId != "" && cmd.Overwrite == false {
  174. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  175. }
  176. return nil
  177. }
  178. func generateNewDashboardUid(sess *DBSession, orgId int64) (string, error) {
  179. for i := 0; i < 3; i++ {
  180. uid := generateNewUid()
  181. exists, err := sess.Where("org_id=? AND uid=?", orgId, uid).Get(&m.Dashboard{})
  182. if err != nil {
  183. return "", err
  184. }
  185. if !exists {
  186. return uid, nil
  187. }
  188. }
  189. return "", m.ErrDashboardFailedGenerateUniqueUid
  190. }
  191. func setHasAcl(sess *DBSession, dash *m.Dashboard) error {
  192. // check if parent has acl
  193. if dash.FolderId > 0 {
  194. var parent m.Dashboard
  195. if hasParent, err := sess.Where("folder_id=?", dash.FolderId).Get(&parent); err != nil {
  196. return err
  197. } else if hasParent && parent.HasAcl {
  198. dash.HasAcl = true
  199. }
  200. }
  201. // check if dash has its own acl
  202. if dash.Id > 0 {
  203. if res, err := sess.Query("SELECT 1 from dashboard_acl WHERE dashboard_id =?", dash.Id); err != nil {
  204. return err
  205. } else {
  206. if len(res) > 0 {
  207. dash.HasAcl = true
  208. }
  209. }
  210. }
  211. return nil
  212. }
  213. func GetDashboard(query *m.GetDashboardQuery) error {
  214. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id, Uid: query.Uid}
  215. has, err := x.Get(&dashboard)
  216. if err != nil {
  217. return err
  218. } else if has == false {
  219. return m.ErrDashboardNotFound
  220. }
  221. dashboard.Data.Set("id", dashboard.Id)
  222. dashboard.Data.Set("uid", dashboard.Uid)
  223. query.Result = &dashboard
  224. return nil
  225. }
  226. type DashboardSearchProjection struct {
  227. Id int64
  228. Uid string
  229. Title string
  230. Slug string
  231. Term string
  232. IsFolder bool
  233. FolderId int64
  234. FolderUid string
  235. FolderSlug string
  236. FolderTitle string
  237. }
  238. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  239. limit := query.Limit
  240. if limit == 0 {
  241. limit = 1000
  242. }
  243. sb := NewSearchBuilder(query.SignedInUser, limit).
  244. WithTags(query.Tags).
  245. WithDashboardIdsIn(query.DashboardIds)
  246. if query.IsStarred {
  247. sb.IsStarred()
  248. }
  249. if len(query.Title) > 0 {
  250. sb.WithTitle(query.Title)
  251. }
  252. if len(query.Type) > 0 {
  253. sb.WithType(query.Type)
  254. }
  255. if len(query.FolderIds) > 0 {
  256. sb.WithFolderIds(query.FolderIds)
  257. }
  258. var res []DashboardSearchProjection
  259. sql, params := sb.ToSql()
  260. err := x.Sql(sql, params...).Find(&res)
  261. if err != nil {
  262. return nil, err
  263. }
  264. return res, nil
  265. }
  266. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  267. res, err := findDashboards(query)
  268. if err != nil {
  269. return err
  270. }
  271. makeQueryResult(query, res)
  272. return nil
  273. }
  274. func getHitType(item DashboardSearchProjection) search.HitType {
  275. var hitType search.HitType
  276. if item.IsFolder {
  277. hitType = search.DashHitFolder
  278. } else {
  279. hitType = search.DashHitDB
  280. }
  281. return hitType
  282. }
  283. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  284. query.Result = make([]*search.Hit, 0)
  285. hits := make(map[int64]*search.Hit)
  286. for _, item := range res {
  287. hit, exists := hits[item.Id]
  288. if !exists {
  289. hit = &search.Hit{
  290. Id: item.Id,
  291. Uid: item.Uid,
  292. Title: item.Title,
  293. Uri: "db/" + item.Slug,
  294. Url: m.GetDashboardFolderUrl(item.IsFolder, item.Uid, item.Slug),
  295. Type: getHitType(item),
  296. FolderId: item.FolderId,
  297. FolderUid: item.FolderUid,
  298. FolderTitle: item.FolderTitle,
  299. Tags: []string{},
  300. }
  301. if item.FolderId > 0 {
  302. hit.FolderUrl = m.GetFolderUrl(item.FolderUid, item.FolderSlug)
  303. }
  304. query.Result = append(query.Result, hit)
  305. hits[item.Id] = hit
  306. }
  307. if len(item.Term) > 0 {
  308. hit.Tags = append(hit.Tags, item.Term)
  309. }
  310. }
  311. }
  312. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  313. sql := `SELECT
  314. COUNT(*) as count,
  315. term
  316. FROM dashboard
  317. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  318. WHERE dashboard.org_id=?
  319. GROUP BY term`
  320. query.Result = make([]*m.DashboardTagCloudItem, 0)
  321. sess := x.Sql(sql, query.OrgId)
  322. err := sess.Find(&query.Result)
  323. return err
  324. }
  325. func GetFoldersForSignedInUser(query *m.GetFoldersForSignedInUserQuery) error {
  326. query.Result = make([]*m.DashboardFolder, 0)
  327. var err error
  328. if query.SignedInUser.OrgRole == m.ROLE_ADMIN {
  329. sql := `SELECT distinct d.id, d.title
  330. FROM dashboard AS d WHERE d.is_folder = ? AND d.org_id = ?
  331. ORDER BY d.title ASC`
  332. err = x.Sql(sql, dialect.BooleanStr(true), query.OrgId).Find(&query.Result)
  333. } else {
  334. params := make([]interface{}, 0)
  335. sql := `SELECT distinct d.id, d.title
  336. FROM dashboard AS d
  337. LEFT JOIN dashboard_acl AS da ON d.id = da.dashboard_id
  338. LEFT JOIN team_member AS ugm ON ugm.team_id = da.team_id
  339. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  340. LEFT JOIN org_user ouRole ON ouRole.role = 'Editor' AND ouRole.user_id = ? AND ouRole.org_id = ?`
  341. params = append(params, query.SignedInUser.UserId)
  342. params = append(params, query.SignedInUser.UserId)
  343. params = append(params, query.OrgId)
  344. sql += ` WHERE
  345. d.org_id = ? AND
  346. d.is_folder = ? AND
  347. (
  348. (d.has_acl = ? AND da.permission > 1 AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  349. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  350. )`
  351. params = append(params, query.OrgId)
  352. params = append(params, dialect.BooleanStr(true))
  353. params = append(params, dialect.BooleanStr(true))
  354. params = append(params, query.SignedInUser.UserId)
  355. params = append(params, query.SignedInUser.UserId)
  356. params = append(params, dialect.BooleanStr(false))
  357. if len(query.Title) > 0 {
  358. sql += " AND d.title " + dialect.LikeStr() + " ?"
  359. params = append(params, "%"+query.Title+"%")
  360. }
  361. sql += ` ORDER BY d.title ASC`
  362. err = x.Sql(sql, params...).Find(&query.Result)
  363. }
  364. return err
  365. }
  366. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  367. return inTransaction(func(sess *DBSession) error {
  368. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  369. has, err := sess.Get(&dashboard)
  370. if err != nil {
  371. return err
  372. } else if has == false {
  373. return m.ErrDashboardNotFound
  374. }
  375. deletes := []string{
  376. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  377. "DELETE FROM star WHERE dashboard_id = ? ",
  378. "DELETE FROM dashboard WHERE id = ?",
  379. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  380. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  381. "DELETE FROM dashboard WHERE folder_id = ?",
  382. "DELETE FROM annotation WHERE dashboard_id = ?",
  383. "DELETE FROM dashboard_provisioning WHERE dashboard_id = ?",
  384. }
  385. for _, sql := range deletes {
  386. _, err := sess.Exec(sql, dashboard.Id)
  387. if err != nil {
  388. return err
  389. }
  390. }
  391. if err := DeleteAlertDefinition(dashboard.Id, sess); err != nil {
  392. return nil
  393. }
  394. return nil
  395. })
  396. }
  397. func GetDashboards(query *m.GetDashboardsQuery) error {
  398. if len(query.DashboardIds) == 0 {
  399. return m.ErrCommandValidationFailed
  400. }
  401. var dashboards = make([]*m.Dashboard, 0)
  402. err := x.In("id", query.DashboardIds).Find(&dashboards)
  403. query.Result = dashboards
  404. if err != nil {
  405. return err
  406. }
  407. return nil
  408. }
  409. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  410. // The function takes in a list of dashboard ids and the user id and role
  411. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  412. if len(query.DashboardIds) == 0 {
  413. return m.ErrCommandValidationFailed
  414. }
  415. if query.OrgRole == m.ROLE_ADMIN {
  416. var permissions = make([]*m.DashboardPermissionForUser, 0)
  417. for _, d := range query.DashboardIds {
  418. permissions = append(permissions, &m.DashboardPermissionForUser{
  419. DashboardId: d,
  420. Permission: m.PERMISSION_ADMIN,
  421. PermissionName: m.PERMISSION_ADMIN.String(),
  422. })
  423. }
  424. query.Result = permissions
  425. return nil
  426. }
  427. params := make([]interface{}, 0)
  428. // check dashboards that have ACLs via user id, team id or role
  429. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  430. FROM dashboard AS d
  431. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  432. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  433. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  434. `
  435. params = append(params, query.UserId)
  436. //check the user's role for dashboards that do not have hasAcl set
  437. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  438. params = append(params, query.UserId)
  439. params = append(params, query.OrgId)
  440. sql += `
  441. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS role
  442. UNION SELECT 2 AS permission, 'Editor' AS role
  443. UNION SELECT 4 AS permission, 'Admin' AS role) pt ON ouRole.role = pt.role
  444. WHERE
  445. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  446. for _, id := range query.DashboardIds {
  447. params = append(params, id)
  448. }
  449. sql += ` AND
  450. d.org_id = ? AND
  451. (
  452. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  453. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  454. )
  455. group by d.id
  456. order by d.id asc`
  457. params = append(params, query.OrgId)
  458. params = append(params, dialect.BooleanStr(true))
  459. params = append(params, query.UserId)
  460. params = append(params, query.UserId)
  461. params = append(params, dialect.BooleanStr(false))
  462. err := x.Sql(sql, params...).Find(&query.Result)
  463. for _, p := range query.Result {
  464. p.PermissionName = p.Permission.String()
  465. }
  466. return err
  467. }
  468. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  469. var dashboards = make([]*m.Dashboard, 0)
  470. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  471. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  472. query.Result = dashboards
  473. if err != nil {
  474. return err
  475. }
  476. return nil
  477. }
  478. type DashboardSlugDTO struct {
  479. Slug string
  480. }
  481. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  482. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  483. var slug = DashboardSlugDTO{}
  484. exists, err := x.SQL(rawSql, query.Id).Get(&slug)
  485. if err != nil {
  486. return err
  487. } else if exists == false {
  488. return m.ErrDashboardNotFound
  489. }
  490. query.Result = slug.Slug
  491. return nil
  492. }
  493. func GetDashboardsBySlug(query *m.GetDashboardsBySlugQuery) error {
  494. var dashboards []*m.Dashboard
  495. if err := x.Where("org_id=? AND slug=?", query.OrgId, query.Slug).Find(&dashboards); err != nil {
  496. return err
  497. }
  498. query.Result = dashboards
  499. return nil
  500. }
  501. func GetDashboardUIDById(query *m.GetDashboardRefByIdQuery) error {
  502. var rawSql = `SELECT uid, slug from dashboard WHERE Id=?`
  503. us := &m.DashboardRef{}
  504. exists, err := x.SQL(rawSql, query.Id).Get(us)
  505. if err != nil {
  506. return err
  507. } else if exists == false {
  508. return m.ErrDashboardNotFound
  509. }
  510. query.Result = us
  511. return nil
  512. }