AccessControl: FGAC permissions for orgs endpoint on frontend (#41050)

* AccessControl: FGAC permissions for orgs endpoint on frontend

Protect org update endpoints

add or refactor missing right messages

cover org page

* removing scopes from orgs

* Perform permission control with global org

* Perform the error handling in case of 403

* Simplify frontend code by requiring read access for sure

* Remove roles I added to decrease the number of changes

* Remove the check for server admin to reduce the number of changes

* change error message

* Cleaning todos

* Remove unecessary changes

* Fix tests

* Update test snapshot

* Update pkg/api/roles.go

Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com>

* Update public/app/features/admin/AdminEditOrgPage.tsx

Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com>

* Format AdminEditOrgPage for linting

* Update public/app/features/admin/AdminEditOrgPage.tsx

Co-authored-by: Vardan Torosyan <vardants@gmail.com>

* Update public/app/features/admin/AdminEditOrgPage.tsx

Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com>

* Update public/app/features/admin/AdminListOrgsPage.tsx

Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com>

* Commit suggestions

* Commit suggestion canRead canWrite

* fix typo

Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com>
Co-authored-by: Vardan Torosyan <vardants@gmail.com>
Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com>
This commit is contained in:
Gabriel MABILLE
2021-11-18 14:10:38 +01:00
committed by GitHub
co-authored by Ursula Kallio Vardan Torosyan Alexander Zobnin
parent 9c2a947605
commit 0ee0a0b7a0
14 changed files with 128 additions and 20 deletions
@@ -7,6 +7,14 @@ import { Organization } from '../../types';
import { mockToolkitActionCreator } from 'test/core/redux/mocks';
import { setOrganizationName } from './state/reducers';
jest.mock('app/core/core', () => {
return {
contextSrv: {
hasPermission: () => true,
},
};
});
const setup = (propOverrides?: object) => {
const props: Props = {
organization: {} as Organization,
+7 -3
View File
@@ -6,10 +6,11 @@ import Page from 'app/core/components/Page/Page';
import OrgProfile from './OrgProfile';
import SharedPreferences from 'app/core/components/SharedPreferences/SharedPreferences';
import { loadOrganization, updateOrganization } from './state/actions';
import { Organization, StoreState } from 'app/types';
import { AccessControlAction, Organization, StoreState } from 'app/types';
import { getNavModel } from 'app/core/selectors/navModel';
import { setOrganizationName } from './state/reducers';
import { VerticalGroup } from '@grafana/ui';
import { contextSrv } from 'app/core/core';
export interface Props {
navModel: NavModel;
@@ -32,14 +33,17 @@ export class OrgDetailsPage extends PureComponent<Props> {
render() {
const { navModel, organization } = this.props;
const isLoading = Object.keys(organization).length === 0;
const canReadOrg = contextSrv.hasPermission(AccessControlAction.OrgsRead);
const canReadPreferences = contextSrv.hasPermission(AccessControlAction.OrgsPreferencesRead);
const canWritePreferences = contextSrv.hasPermission(AccessControlAction.OrgsPreferencesWrite);
return (
<Page navModel={navModel}>
<Page.Contents isLoading={isLoading}>
{!isLoading && (
<VerticalGroup spacing="lg">
<OrgProfile onSubmit={this.onUpdateOrganization} orgName={organization.name} />
<SharedPreferences resourceUri="org" />
{canReadOrg && <OrgProfile onSubmit={this.onUpdateOrganization} orgName={organization.name} />}
{canReadPreferences && <SharedPreferences resourceUri="org" disabled={!canWritePreferences} />}
</VerticalGroup>
)}
</Page.Contents>
@@ -2,6 +2,14 @@ import React from 'react';
import { shallow } from 'enzyme';
import OrgProfile, { Props } from './OrgProfile';
jest.mock('app/core/core', () => {
return {
contextSrv: {
hasPermission: () => true,
},
};
});
const setup = () => {
const props: Props = {
orgName: 'Main org',
+5 -1
View File
@@ -1,5 +1,7 @@
import React, { FC } from 'react';
import { Input, Field, FieldSet, Button, Form } from '@grafana/ui';
import { contextSrv } from 'app/core/core';
import { AccessControlAction } from 'app/types';
export interface Props {
orgName: string;
@@ -11,10 +13,12 @@ interface FormDTO {
}
const OrgProfile: FC<Props> = ({ onSubmit, orgName }) => {
const canWriteOrg = contextSrv.hasPermission(AccessControlAction.OrgsWrite);
return (
<Form defaultValues={{ orgName }} onSubmit={({ orgName }: FormDTO) => onSubmit(orgName)}>
{({ register }) => (
<FieldSet label="Organization profile">
<FieldSet label="Organization profile" disabled={!canWriteOrg}>
<Field label="Organization name">
<Input id="org-name-input" type="text" {...register('orgName', { required: true })} />
</Field>
@@ -43,6 +43,7 @@ exports[`Render should render organization and preferences 1`] = `
orgName="Cool org"
/>
<SharedPreferences
disabled={false}
resourceUri="org"
/>
</VerticalGroup>