dashboard.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497
  1. package sqlstore
  2. import (
  3. "strings"
  4. "time"
  5. "github.com/grafana/grafana/pkg/bus"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. m "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/services/search"
  9. )
  10. func init() {
  11. bus.AddHandler("sql", SaveDashboard)
  12. bus.AddHandler("sql", GetDashboard)
  13. bus.AddHandler("sql", GetDashboards)
  14. bus.AddHandler("sql", DeleteDashboard)
  15. bus.AddHandler("sql", SearchDashboards)
  16. bus.AddHandler("sql", GetDashboardTags)
  17. bus.AddHandler("sql", GetDashboardSlugById)
  18. bus.AddHandler("sql", GetDashboardsByPluginId)
  19. bus.AddHandler("sql", GetFoldersForSignedInUser)
  20. bus.AddHandler("sql", GetDashboardPermissionsForUser)
  21. }
  22. func SaveDashboard(cmd *m.SaveDashboardCommand) error {
  23. return inTransaction(func(sess *DBSession) error {
  24. dash := cmd.GetDashboardModel()
  25. // try get existing dashboard
  26. var existing, sameTitle m.Dashboard
  27. if dash.Id > 0 {
  28. dashWithIdExists, err := sess.Where("id=? AND org_id=?", dash.Id, dash.OrgId).Get(&existing)
  29. if err != nil {
  30. return err
  31. }
  32. if !dashWithIdExists {
  33. return m.ErrDashboardNotFound
  34. }
  35. // check for is someone else has written in between
  36. if dash.Version != existing.Version {
  37. if cmd.Overwrite {
  38. dash.Version = existing.Version
  39. } else {
  40. return m.ErrDashboardVersionMismatch
  41. }
  42. }
  43. // do not allow plugin dashboard updates without overwrite flag
  44. if existing.PluginId != "" && cmd.Overwrite == false {
  45. return m.UpdatePluginDashboardError{PluginId: existing.PluginId}
  46. }
  47. }
  48. sameTitleExists, err := sess.Where("org_id=? AND slug=?", dash.OrgId, dash.Slug).Get(&sameTitle)
  49. if err != nil {
  50. return err
  51. }
  52. if sameTitleExists {
  53. // another dashboard with same name
  54. if dash.Id != sameTitle.Id {
  55. if cmd.Overwrite {
  56. dash.Id = sameTitle.Id
  57. dash.Version = sameTitle.Version
  58. } else {
  59. return m.ErrDashboardWithSameNameExists
  60. }
  61. }
  62. }
  63. err = setHasAcl(sess, dash)
  64. if err != nil {
  65. return err
  66. }
  67. parentVersion := dash.Version
  68. affectedRows := int64(0)
  69. if dash.Id == 0 {
  70. dash.Version = 1
  71. metrics.M_Api_Dashboard_Insert.Inc()
  72. dash.Data.Set("version", dash.Version)
  73. affectedRows, err = sess.Insert(dash)
  74. } else {
  75. dash.Version++
  76. dash.Data.Set("version", dash.Version)
  77. if !cmd.UpdatedAt.IsZero() {
  78. dash.Updated = cmd.UpdatedAt
  79. }
  80. affectedRows, err = sess.MustCols("folder_id", "has_acl").Id(dash.Id).Update(dash)
  81. }
  82. if err != nil {
  83. return err
  84. }
  85. if affectedRows == 0 {
  86. return m.ErrDashboardNotFound
  87. }
  88. dashVersion := &m.DashboardVersion{
  89. DashboardId: dash.Id,
  90. ParentVersion: parentVersion,
  91. RestoredFrom: cmd.RestoredFrom,
  92. Version: dash.Version,
  93. Created: time.Now(),
  94. CreatedBy: dash.UpdatedBy,
  95. Message: cmd.Message,
  96. Data: dash.Data,
  97. }
  98. // insert version entry
  99. if affectedRows, err = sess.Insert(dashVersion); err != nil {
  100. return err
  101. } else if affectedRows == 0 {
  102. return m.ErrDashboardNotFound
  103. }
  104. // delete existing tags
  105. _, err = sess.Exec("DELETE FROM dashboard_tag WHERE dashboard_id=?", dash.Id)
  106. if err != nil {
  107. return err
  108. }
  109. // insert new tags
  110. tags := dash.GetTags()
  111. if len(tags) > 0 {
  112. for _, tag := range tags {
  113. if _, err := sess.Insert(&DashboardTag{DashboardId: dash.Id, Term: tag}); err != nil {
  114. return err
  115. }
  116. }
  117. }
  118. cmd.Result = dash
  119. return err
  120. })
  121. }
  122. func setHasAcl(sess *DBSession, dash *m.Dashboard) error {
  123. // check if parent has acl
  124. if dash.FolderId > 0 {
  125. var parent m.Dashboard
  126. if hasParent, err := sess.Where("folder_id=?", dash.FolderId).Get(&parent); err != nil {
  127. return err
  128. } else if hasParent && parent.HasAcl {
  129. dash.HasAcl = true
  130. }
  131. }
  132. // check if dash has its own acl
  133. if dash.Id > 0 {
  134. if res, err := sess.Query("SELECT 1 from dashboard_acl WHERE dashboard_id =?", dash.Id); err != nil {
  135. return err
  136. } else {
  137. if len(res) > 0 {
  138. dash.HasAcl = true
  139. }
  140. }
  141. }
  142. return nil
  143. }
  144. func GetDashboard(query *m.GetDashboardQuery) error {
  145. dashboard := m.Dashboard{Slug: query.Slug, OrgId: query.OrgId, Id: query.Id}
  146. has, err := x.Get(&dashboard)
  147. if err != nil {
  148. return err
  149. } else if has == false {
  150. return m.ErrDashboardNotFound
  151. }
  152. dashboard.Data.Set("id", dashboard.Id)
  153. query.Result = &dashboard
  154. return nil
  155. }
  156. type DashboardSearchProjection struct {
  157. Id int64
  158. Title string
  159. Slug string
  160. Term string
  161. IsFolder bool
  162. FolderId int64
  163. FolderSlug string
  164. FolderTitle string
  165. }
  166. func findDashboards(query *search.FindPersistedDashboardsQuery) ([]DashboardSearchProjection, error) {
  167. limit := query.Limit
  168. if limit == 0 {
  169. limit = 1000
  170. }
  171. sb := NewSearchBuilder(query.SignedInUser, limit).
  172. WithTags(query.Tags).
  173. WithDashboardIdsIn(query.DashboardIds)
  174. if query.IsStarred {
  175. sb.IsStarred()
  176. }
  177. if len(query.Title) > 0 {
  178. sb.WithTitle(query.Title)
  179. }
  180. if len(query.Type) > 0 {
  181. sb.WithType(query.Type)
  182. }
  183. if len(query.FolderIds) > 0 {
  184. sb.WithFolderIds(query.FolderIds)
  185. }
  186. var res []DashboardSearchProjection
  187. sql, params := sb.ToSql()
  188. err := x.Sql(sql, params...).Find(&res)
  189. if err != nil {
  190. return nil, err
  191. }
  192. return res, nil
  193. }
  194. func SearchDashboards(query *search.FindPersistedDashboardsQuery) error {
  195. res, err := findDashboards(query)
  196. if err != nil {
  197. return err
  198. }
  199. makeQueryResult(query, res)
  200. return nil
  201. }
  202. func getHitType(item DashboardSearchProjection) search.HitType {
  203. var hitType search.HitType
  204. if item.IsFolder {
  205. hitType = search.DashHitFolder
  206. } else {
  207. hitType = search.DashHitDB
  208. }
  209. return hitType
  210. }
  211. func makeQueryResult(query *search.FindPersistedDashboardsQuery, res []DashboardSearchProjection) {
  212. query.Result = make([]*search.Hit, 0)
  213. hits := make(map[int64]*search.Hit)
  214. for _, item := range res {
  215. hit, exists := hits[item.Id]
  216. if !exists {
  217. hit = &search.Hit{
  218. Id: item.Id,
  219. Title: item.Title,
  220. Uri: "db/" + item.Slug,
  221. Slug: item.Slug,
  222. Type: getHitType(item),
  223. FolderId: item.FolderId,
  224. FolderTitle: item.FolderTitle,
  225. FolderSlug: item.FolderSlug,
  226. Tags: []string{},
  227. }
  228. query.Result = append(query.Result, hit)
  229. hits[item.Id] = hit
  230. }
  231. if len(item.Term) > 0 {
  232. hit.Tags = append(hit.Tags, item.Term)
  233. }
  234. }
  235. }
  236. func GetDashboardTags(query *m.GetDashboardTagsQuery) error {
  237. sql := `SELECT
  238. COUNT(*) as count,
  239. term
  240. FROM dashboard
  241. INNER JOIN dashboard_tag on dashboard_tag.dashboard_id = dashboard.id
  242. WHERE dashboard.org_id=?
  243. GROUP BY term`
  244. query.Result = make([]*m.DashboardTagCloudItem, 0)
  245. sess := x.Sql(sql, query.OrgId)
  246. err := sess.Find(&query.Result)
  247. return err
  248. }
  249. func GetFoldersForSignedInUser(query *m.GetFoldersForSignedInUserQuery) error {
  250. query.Result = make([]*m.DashboardFolder, 0)
  251. var err error
  252. if query.SignedInUser.OrgRole == m.ROLE_ADMIN {
  253. sql := `SELECT distinct d.id, d.title
  254. FROM dashboard AS d WHERE d.is_folder = ?
  255. ORDER BY d.title ASC`
  256. err = x.Sql(sql, dialect.BooleanStr(true)).Find(&query.Result)
  257. } else {
  258. params := make([]interface{}, 0)
  259. sql := `SELECT distinct d.id, d.title
  260. FROM dashboard AS d
  261. LEFT JOIN dashboard_acl AS da ON d.id = da.dashboard_id
  262. LEFT JOIN team_member AS ugm ON ugm.team_id = da.team_id
  263. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  264. LEFT JOIN org_user ouRole ON ouRole.role = 'Editor' AND ouRole.user_id = ? AND ouRole.org_id = ?`
  265. params = append(params, query.SignedInUser.UserId)
  266. params = append(params, query.SignedInUser.UserId)
  267. params = append(params, query.OrgId)
  268. sql += `WHERE
  269. d.org_id = ? AND
  270. d.is_folder = 1 AND
  271. (
  272. (d.has_acl = 1 AND da.permission > 1 AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  273. OR (d.has_acl = 0 AND ouRole.id IS NOT NULL)
  274. )`
  275. params = append(params, query.OrgId)
  276. params = append(params, query.SignedInUser.UserId)
  277. params = append(params, query.SignedInUser.UserId)
  278. if len(query.Title) > 0 {
  279. sql += " AND d.title " + dialect.LikeStr() + " ?"
  280. params = append(params, "%"+query.Title+"%")
  281. }
  282. sql += ` ORDER BY d.title ASC`
  283. err = x.Sql(sql, params...).Find(&query.Result)
  284. }
  285. return err
  286. }
  287. func DeleteDashboard(cmd *m.DeleteDashboardCommand) error {
  288. return inTransaction(func(sess *DBSession) error {
  289. dashboard := m.Dashboard{Id: cmd.Id, OrgId: cmd.OrgId}
  290. has, err := sess.Get(&dashboard)
  291. if err != nil {
  292. return err
  293. } else if has == false {
  294. return m.ErrDashboardNotFound
  295. }
  296. deletes := []string{
  297. "DELETE FROM dashboard_tag WHERE dashboard_id = ? ",
  298. "DELETE FROM star WHERE dashboard_id = ? ",
  299. "DELETE FROM dashboard WHERE id = ?",
  300. "DELETE FROM playlist_item WHERE type = 'dashboard_by_id' AND value = ?",
  301. "DELETE FROM dashboard_version WHERE dashboard_id = ?",
  302. "DELETE FROM dashboard WHERE folder_id = ?",
  303. "DELETE FROM annotation WHERE dashboard_id = ?",
  304. }
  305. for _, sql := range deletes {
  306. _, err := sess.Exec(sql, dashboard.Id)
  307. if err != nil {
  308. return err
  309. }
  310. }
  311. if err := DeleteAlertDefinition(dashboard.Id, sess); err != nil {
  312. return nil
  313. }
  314. return nil
  315. })
  316. }
  317. func GetDashboards(query *m.GetDashboardsQuery) error {
  318. if len(query.DashboardIds) == 0 {
  319. return m.ErrCommandValidationFailed
  320. }
  321. var dashboards = make([]*m.Dashboard, 0)
  322. err := x.In("id", query.DashboardIds).Find(&dashboards)
  323. query.Result = dashboards
  324. if err != nil {
  325. return err
  326. }
  327. return nil
  328. }
  329. // GetDashboardPermissionsForUser returns the maximum permission the specified user has for a dashboard(s)
  330. // The function takes in a list of dashboard ids and the user id and role
  331. func GetDashboardPermissionsForUser(query *m.GetDashboardPermissionsForUserQuery) error {
  332. if len(query.DashboardIds) == 0 {
  333. return m.ErrCommandValidationFailed
  334. }
  335. if query.OrgRole == m.ROLE_ADMIN {
  336. var permissions = make([]*m.DashboardPermissionForUser, 0)
  337. for _, d := range query.DashboardIds {
  338. permissions = append(permissions, &m.DashboardPermissionForUser{
  339. DashboardId: d,
  340. Permission: m.PERMISSION_ADMIN,
  341. PermissionName: m.PERMISSION_ADMIN.String(),
  342. })
  343. }
  344. query.Result = permissions
  345. return nil
  346. }
  347. params := make([]interface{}, 0)
  348. // check dashboards that have ACLs via user id, team id or role
  349. sql := `SELECT d.id AS dashboard_id, MAX(COALESCE(da.permission, pt.permission)) AS permission
  350. FROM dashboard AS d
  351. LEFT JOIN dashboard_acl as da on d.folder_id = da.dashboard_id or d.id = da.dashboard_id
  352. LEFT JOIN team_member as ugm on ugm.team_id = da.team_id
  353. LEFT JOIN org_user ou ON ou.role = da.role AND ou.user_id = ?
  354. `
  355. params = append(params, query.UserId)
  356. //check the user's role for dashboards that do not have hasAcl set
  357. sql += `LEFT JOIN org_user ouRole ON ouRole.user_id = ? AND ouRole.org_id = ?`
  358. params = append(params, query.UserId)
  359. params = append(params, query.OrgId)
  360. sql += `
  361. LEFT JOIN (SELECT 1 AS permission, 'Viewer' AS 'role'
  362. UNION SELECT 2 AS permission, 'Editor' AS 'role'
  363. UNION SELECT 4 AS permission, 'Admin' AS 'role') pt ON ouRole.role = pt.role
  364. WHERE
  365. d.Id IN (?` + strings.Repeat(",?", len(query.DashboardIds)-1) + `) `
  366. for _, id := range query.DashboardIds {
  367. params = append(params, id)
  368. }
  369. sql += ` AND
  370. d.org_id = ? AND
  371. (
  372. (d.has_acl = ? AND (da.user_id = ? OR ugm.user_id = ? OR ou.id IS NOT NULL))
  373. OR (d.has_acl = ? AND ouRole.id IS NOT NULL)
  374. )
  375. group by d.id
  376. order by d.id asc`
  377. params = append(params, dialect.BooleanStr(true))
  378. params = append(params, query.OrgId)
  379. params = append(params, query.UserId)
  380. params = append(params, query.UserId)
  381. params = append(params, dialect.BooleanStr(false))
  382. err := x.Sql(sql, params...).Find(&query.Result)
  383. for _, p := range query.Result {
  384. p.PermissionName = p.Permission.String()
  385. }
  386. return err
  387. }
  388. func GetDashboardsByPluginId(query *m.GetDashboardsByPluginIdQuery) error {
  389. var dashboards = make([]*m.Dashboard, 0)
  390. whereExpr := "org_id=? AND plugin_id=? AND is_folder=" + dialect.BooleanStr(false)
  391. err := x.Where(whereExpr, query.OrgId, query.PluginId).Find(&dashboards)
  392. query.Result = dashboards
  393. if err != nil {
  394. return err
  395. }
  396. return nil
  397. }
  398. type DashboardSlugDTO struct {
  399. Slug string
  400. }
  401. func GetDashboardSlugById(query *m.GetDashboardSlugByIdQuery) error {
  402. var rawSql = `SELECT slug from dashboard WHERE Id=?`
  403. var slug = DashboardSlugDTO{}
  404. exists, err := x.Sql(rawSql, query.Id).Get(&slug)
  405. if err != nil {
  406. return err
  407. } else if exists == false {
  408. return m.ErrDashboardNotFound
  409. }
  410. query.Result = slug.Slug
  411. return nil
  412. }