org_users.go 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194
  1. package api
  2. import (
  3. "github.com/grafana/grafana/pkg/api/dtos"
  4. "github.com/grafana/grafana/pkg/bus"
  5. "github.com/grafana/grafana/pkg/models"
  6. )
  7. // POST /api/org/users
  8. func AddOrgUserToCurrentOrg(c *models.ReqContext, cmd models.AddOrgUserCommand) Response {
  9. cmd.OrgId = c.OrgId
  10. return addOrgUserHelper(cmd)
  11. }
  12. // POST /api/orgs/:orgId/users
  13. func AddOrgUser(c *models.ReqContext, cmd models.AddOrgUserCommand) Response {
  14. cmd.OrgId = c.ParamsInt64(":orgId")
  15. return addOrgUserHelper(cmd)
  16. }
  17. func addOrgUserHelper(cmd models.AddOrgUserCommand) Response {
  18. if !cmd.Role.IsValid() {
  19. return Error(400, "Invalid role specified", nil)
  20. }
  21. userQuery := models.GetUserByLoginQuery{LoginOrEmail: cmd.LoginOrEmail}
  22. err := bus.Dispatch(&userQuery)
  23. if err != nil {
  24. return Error(404, "User not found", nil)
  25. }
  26. userToAdd := userQuery.Result
  27. cmd.UserId = userToAdd.Id
  28. if err := bus.Dispatch(&cmd); err != nil {
  29. if err == models.ErrOrgUserAlreadyAdded {
  30. return Error(409, "User is already member of this organization", nil)
  31. }
  32. return Error(500, "Could not add user to organization", err)
  33. }
  34. return Success("User added to organization")
  35. }
  36. // GET /api/org/users
  37. func GetOrgUsersForCurrentOrg(c *models.ReqContext) Response {
  38. result, err := getOrgUsersHelper(c.OrgId, c.Query("query"), c.QueryInt("limit"))
  39. if err != nil {
  40. return Error(500, "Failed to get users for current organization", err)
  41. }
  42. return JSON(200, result)
  43. }
  44. // GET /api/org/users/lookup
  45. func GetOrgUsersForCurrentOrgLookup(c *models.ReqContext) Response {
  46. isAdmin, err := isOrgAdminFolderAdminOrTeamAdmin(c)
  47. if err != nil {
  48. return Error(500, "Failed to get users for current organization", err)
  49. }
  50. if !isAdmin {
  51. return Error(403, "Permission denied", nil)
  52. }
  53. orgUsers, err := getOrgUsersHelper(c.OrgId, c.Query("query"), c.QueryInt("limit"))
  54. if err != nil {
  55. return Error(500, "Failed to get users for current organization", err)
  56. }
  57. result := make([]*dtos.UserLookupDTO, 0)
  58. for _, u := range orgUsers {
  59. result = append(result, &dtos.UserLookupDTO{
  60. UserID: u.UserId,
  61. Login: u.Login,
  62. AvatarURL: u.AvatarUrl,
  63. })
  64. }
  65. return JSON(200, result)
  66. }
  67. func isOrgAdminFolderAdminOrTeamAdmin(c *models.ReqContext) (bool, error) {
  68. if c.OrgRole == models.ROLE_ADMIN {
  69. return true, nil
  70. }
  71. hasAdminPermissionInFoldersQuery := models.HasAdminPermissionInFoldersQuery{SignedInUser: c.SignedInUser}
  72. if err := bus.Dispatch(&hasAdminPermissionInFoldersQuery); err != nil {
  73. return false, err
  74. }
  75. if hasAdminPermissionInFoldersQuery.Result {
  76. return true, nil
  77. }
  78. isAdminOfTeamsQuery := models.IsAdminOfTeamsQuery{SignedInUser: c.SignedInUser}
  79. if err := bus.Dispatch(&isAdminOfTeamsQuery); err != nil {
  80. return false, err
  81. }
  82. return isAdminOfTeamsQuery.Result, nil
  83. }
  84. // GET /api/orgs/:orgId/users
  85. func GetOrgUsers(c *models.ReqContext) Response {
  86. result, err := getOrgUsersHelper(c.ParamsInt64(":orgId"), "", 0)
  87. if err != nil {
  88. return Error(500, "Failed to get users for organization", err)
  89. }
  90. return JSON(200, result)
  91. }
  92. func getOrgUsersHelper(orgID int64, query string, limit int) ([]*models.OrgUserDTO, error) {
  93. q := models.GetOrgUsersQuery{
  94. OrgId: orgID,
  95. Query: query,
  96. Limit: limit,
  97. }
  98. if err := bus.Dispatch(&q); err != nil {
  99. return nil, err
  100. }
  101. for _, user := range q.Result {
  102. user.AvatarUrl = dtos.GetGravatarUrl(user.Email)
  103. }
  104. return q.Result, nil
  105. }
  106. // PATCH /api/org/users/:userId
  107. func UpdateOrgUserForCurrentOrg(c *models.ReqContext, cmd models.UpdateOrgUserCommand) Response {
  108. cmd.OrgId = c.OrgId
  109. cmd.UserId = c.ParamsInt64(":userId")
  110. return updateOrgUserHelper(cmd)
  111. }
  112. // PATCH /api/orgs/:orgId/users/:userId
  113. func UpdateOrgUser(c *models.ReqContext, cmd models.UpdateOrgUserCommand) Response {
  114. cmd.OrgId = c.ParamsInt64(":orgId")
  115. cmd.UserId = c.ParamsInt64(":userId")
  116. return updateOrgUserHelper(cmd)
  117. }
  118. func updateOrgUserHelper(cmd models.UpdateOrgUserCommand) Response {
  119. if !cmd.Role.IsValid() {
  120. return Error(400, "Invalid role specified", nil)
  121. }
  122. if err := bus.Dispatch(&cmd); err != nil {
  123. if err == models.ErrLastOrgAdmin {
  124. return Error(400, "Cannot change role so that there is no organization admin left", nil)
  125. }
  126. return Error(500, "Failed update org user", err)
  127. }
  128. return Success("Organization user updated")
  129. }
  130. // DELETE /api/org/users/:userId
  131. func RemoveOrgUserForCurrentOrg(c *models.ReqContext) Response {
  132. return removeOrgUserHelper(&models.RemoveOrgUserCommand{
  133. UserId: c.ParamsInt64(":userId"),
  134. OrgId: c.OrgId,
  135. ShouldDeleteOrphanedUser: true,
  136. })
  137. }
  138. // DELETE /api/orgs/:orgId/users/:userId
  139. func RemoveOrgUser(c *models.ReqContext) Response {
  140. return removeOrgUserHelper(&models.RemoveOrgUserCommand{
  141. UserId: c.ParamsInt64(":userId"),
  142. OrgId: c.ParamsInt64(":orgId"),
  143. })
  144. }
  145. func removeOrgUserHelper(cmd *models.RemoveOrgUserCommand) Response {
  146. if err := bus.Dispatch(cmd); err != nil {
  147. if err == models.ErrLastOrgAdmin {
  148. return Error(400, "Cannot remove last organization admin", nil)
  149. }
  150. return Error(500, "Failed to remove user from organization", err)
  151. }
  152. if cmd.UserWasDeleted {
  153. return Success("User deleted")
  154. }
  155. return Success("User removed from organization")
  156. }