mirror of
https://github.com/grafana/grafana.git
synced 2026-09-05 04:40:13 -05:00
AccessControl: FGAC permissions for orgs endpoint on frontend (#41050)
* AccessControl: FGAC permissions for orgs endpoint on frontend Protect org update endpoints add or refactor missing right messages cover org page * removing scopes from orgs * Perform permission control with global org * Perform the error handling in case of 403 * Simplify frontend code by requiring read access for sure * Remove roles I added to decrease the number of changes * Remove the check for server admin to reduce the number of changes * change error message * Cleaning todos * Remove unecessary changes * Fix tests * Update test snapshot * Update pkg/api/roles.go Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com> * Update public/app/features/admin/AdminEditOrgPage.tsx Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com> * Format AdminEditOrgPage for linting * Update public/app/features/admin/AdminEditOrgPage.tsx Co-authored-by: Vardan Torosyan <vardants@gmail.com> * Update public/app/features/admin/AdminEditOrgPage.tsx Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com> * Update public/app/features/admin/AdminListOrgsPage.tsx Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com> * Commit suggestions * Commit suggestion canRead canWrite * fix typo Co-authored-by: Ursula Kallio <73951760+osg-grafana@users.noreply.github.com> Co-authored-by: Vardan Torosyan <vardants@gmail.com> Co-authored-by: Alexander Zobnin <alexanderzobnin@gmail.com>
This commit is contained in:
co-authored by
Ursula Kallio
Vardan Torosyan
Alexander Zobnin
parent
9c2a947605
commit
0ee0a0b7a0
@@ -7,6 +7,14 @@ import { Organization } from '../../types';
|
||||
import { mockToolkitActionCreator } from 'test/core/redux/mocks';
|
||||
import { setOrganizationName } from './state/reducers';
|
||||
|
||||
jest.mock('app/core/core', () => {
|
||||
return {
|
||||
contextSrv: {
|
||||
hasPermission: () => true,
|
||||
},
|
||||
};
|
||||
});
|
||||
|
||||
const setup = (propOverrides?: object) => {
|
||||
const props: Props = {
|
||||
organization: {} as Organization,
|
||||
|
||||
@@ -6,10 +6,11 @@ import Page from 'app/core/components/Page/Page';
|
||||
import OrgProfile from './OrgProfile';
|
||||
import SharedPreferences from 'app/core/components/SharedPreferences/SharedPreferences';
|
||||
import { loadOrganization, updateOrganization } from './state/actions';
|
||||
import { Organization, StoreState } from 'app/types';
|
||||
import { AccessControlAction, Organization, StoreState } from 'app/types';
|
||||
import { getNavModel } from 'app/core/selectors/navModel';
|
||||
import { setOrganizationName } from './state/reducers';
|
||||
import { VerticalGroup } from '@grafana/ui';
|
||||
import { contextSrv } from 'app/core/core';
|
||||
|
||||
export interface Props {
|
||||
navModel: NavModel;
|
||||
@@ -32,14 +33,17 @@ export class OrgDetailsPage extends PureComponent<Props> {
|
||||
render() {
|
||||
const { navModel, organization } = this.props;
|
||||
const isLoading = Object.keys(organization).length === 0;
|
||||
const canReadOrg = contextSrv.hasPermission(AccessControlAction.OrgsRead);
|
||||
const canReadPreferences = contextSrv.hasPermission(AccessControlAction.OrgsPreferencesRead);
|
||||
const canWritePreferences = contextSrv.hasPermission(AccessControlAction.OrgsPreferencesWrite);
|
||||
|
||||
return (
|
||||
<Page navModel={navModel}>
|
||||
<Page.Contents isLoading={isLoading}>
|
||||
{!isLoading && (
|
||||
<VerticalGroup spacing="lg">
|
||||
<OrgProfile onSubmit={this.onUpdateOrganization} orgName={organization.name} />
|
||||
<SharedPreferences resourceUri="org" />
|
||||
{canReadOrg && <OrgProfile onSubmit={this.onUpdateOrganization} orgName={organization.name} />}
|
||||
{canReadPreferences && <SharedPreferences resourceUri="org" disabled={!canWritePreferences} />}
|
||||
</VerticalGroup>
|
||||
)}
|
||||
</Page.Contents>
|
||||
|
||||
@@ -2,6 +2,14 @@ import React from 'react';
|
||||
import { shallow } from 'enzyme';
|
||||
import OrgProfile, { Props } from './OrgProfile';
|
||||
|
||||
jest.mock('app/core/core', () => {
|
||||
return {
|
||||
contextSrv: {
|
||||
hasPermission: () => true,
|
||||
},
|
||||
};
|
||||
});
|
||||
|
||||
const setup = () => {
|
||||
const props: Props = {
|
||||
orgName: 'Main org',
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
import React, { FC } from 'react';
|
||||
import { Input, Field, FieldSet, Button, Form } from '@grafana/ui';
|
||||
import { contextSrv } from 'app/core/core';
|
||||
import { AccessControlAction } from 'app/types';
|
||||
|
||||
export interface Props {
|
||||
orgName: string;
|
||||
@@ -11,10 +13,12 @@ interface FormDTO {
|
||||
}
|
||||
|
||||
const OrgProfile: FC<Props> = ({ onSubmit, orgName }) => {
|
||||
const canWriteOrg = contextSrv.hasPermission(AccessControlAction.OrgsWrite);
|
||||
|
||||
return (
|
||||
<Form defaultValues={{ orgName }} onSubmit={({ orgName }: FormDTO) => onSubmit(orgName)}>
|
||||
{({ register }) => (
|
||||
<FieldSet label="Organization profile">
|
||||
<FieldSet label="Organization profile" disabled={!canWriteOrg}>
|
||||
<Field label="Organization name">
|
||||
<Input id="org-name-input" type="text" {...register('orgName', { required: true })} />
|
||||
</Field>
|
||||
|
||||
@@ -43,6 +43,7 @@ exports[`Render should render organization and preferences 1`] = `
|
||||
orgName="Cool org"
|
||||
/>
|
||||
<SharedPreferences
|
||||
disabled={false}
|
||||
resourceUri="org"
|
||||
/>
|
||||
</VerticalGroup>
|
||||
|
||||
Reference in New Issue
Block a user