grafana/pkg/api
colin-stuart 6abe99efd6
Auth: Passwordless Login Option Using Magic Links (#95436)
* initial passwordless client

* passwordless login page

* Working basic e2e flow

* Add todo comments

* Improve the passwordless login flow

* improved passwordless login, backend for passwordless signup

* add expiration to emails

* update email templates & render username & name fields on signup

* improve email templates

* change login page text while awaiting passwordless code

* fix merge conflicts

* use claims.TypeUser

* add initial passwordless tests

* better error messages

* simplified error name

* remove completed TODOs

* linting & minor test improvements & rename passwordless routes

* more linting fixes

* move code generation to its own func, use locationService to get query params

* fix ampersand in email templates & use passwordless api routes in LoginCtrl

* txt emails more closely match html email copy

* move passwordless auth behind experimental feature toggle

* fix PasswordlessLogin property failing typecheck

* make update-workspace

* user correct placeholder

* Update emails/templates/passwordless_verify_existing_user.txt

Co-authored-by: Dan Cech <dcech@grafana.com>

* Update emails/templates/passwordless_verify_existing_user.mjml

Co-authored-by: Dan Cech <dcech@grafana.com>

* Update emails/templates/passwordless_verify_new_user.txt

Co-authored-by: Dan Cech <dcech@grafana.com>

* Update emails/templates/passwordless_verify_new_user.txt

Co-authored-by: Dan Cech <dcech@grafana.com>

* Update emails/templates/passwordless_verify_new_user.mjml

Co-authored-by: Dan Cech <dcech@grafana.com>

* use &amp; in email templates

* Update emails/templates/passwordless_verify_existing_user.txt

Co-authored-by: Dan Cech <dcech@grafana.com>

* remove IP address validation

* struct for passwordless settings

* revert go.work.sum changes

* mock locationService.getSearch in failing test

---------

Co-authored-by: Mihaly Gyongyosi <mgyongyosi@users.noreply.github.com>
Co-authored-by: Dan Cech <dcech@grafana.com>
2024-11-14 08:50:55 -05:00
..
apierrors Dashboards: Remove unique name constraints (#90687) 2024-10-29 08:58:39 +03:00
avatar Chore: Remove public vars in setting package (#81018) 2024-01-23 12:36:22 +01:00
datasource mssql: prepare logs-handling for decouple-datasource changes (#79214) 2023-12-11 09:14:06 +01:00
dtos Auth: Passwordless Login Option Using Magic Links (#95436) 2024-11-14 08:50:55 -05:00
frontendlogging Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
pluginproxy Alert: unexpected error log occur (#95491) 2024-10-28 15:34:07 +01:00
response Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
routing Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
static API: Extract OpenAPI specification from source code using go-swagger (#40528) 2022-02-08 13:38:43 +01:00
webassets Frontend: Extract CSS imports into files (#94655) 2024-10-16 11:10:34 +02:00
accesscontrol.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
admin_encryption.go Config: Add configuration option to define custom user-facing general error message for certain error types (#70023) 2023-06-16 10:46:47 -05:00
admin_provisioning_test.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_provisioning.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_test.go Auth: Add anonymous users view and stats (#78685) 2023-11-29 17:58:41 +01:00
admin_users_test.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00
admin_users.go Users: Allow specifying user UIDs in params (#95424) 2024-10-30 14:14:42 +01:00
admin.go Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
alerting.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
annotations_test.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
annotations.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
api_test.go Chore: Update test database initialization (#81673) 2024-02-09 09:35:39 -05:00
api.go Auth: Passwordless Login Option Using Magic Links (#95436) 2024-11-14 08:50:55 -05:00
apikey.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
basic_auth_test.go Macaron: remove custom Request type (#37874) 2021-09-01 11:18:30 +02:00
basic_auth.go Macaron: remove custom Request type (#37874) 2021-09-01 11:18:30 +02:00
common_test.go Auth: Use sessionStorage instead of cookie for automatic redirection (#92759) 2024-09-24 18:38:09 +02:00
dashboard_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_permission.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_snapshot_test.go Zanzana: Evaluate permissions alongside with RBAC engine (#90064) 2024-07-05 11:31:23 +02:00
dashboard_snapshot.go K8s: Improve identity mapping setup (#89450) 2024-06-20 17:53:07 +03:00
dashboard_test.go Dashboards: Remove unique name constraints (#90687) 2024-10-29 08:58:39 +03:00
dashboard.go Instrument tracing across dashboards (#91937) 2024-08-29 22:26:15 -08:00
dataproxy.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
datasources_test.go LBAC for datasources: Move validation of rules from datasources to LBAC Rules (#94622) 2024-10-25 10:07:53 +01:00
datasources.go LBAC for datasources: Move validation of rules from datasources to LBAC Rules (#94622) 2024-10-25 10:07:53 +01:00
ds_query_test.go Instrument tracing across accesscontrol (#91864) 2024-08-16 14:08:19 -08:00
ds_query.go Plugins: Remove datasourceQueryMultiStatus feature toggle (#90191) 2024-07-10 11:15:10 +02:00
fakes.go Plugins: Make it possible to support multiple plugin versions (#82116) 2024-02-12 12:47:49 +01:00
folder_bench_test.go Zanzana: periodic sync of team members (#94752) 2024-10-17 15:28:33 +02:00
folder_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_permission.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_test.go Dashboards: Remove unique name constraints (#90687) 2024-10-29 08:58:39 +03:00
folder.go Users: Allow specifying user UIDs in params (#95424) 2024-10-30 14:14:42 +01:00
frontend_logging_test.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
frontend_logging.go Chore: Bump Go to 1.23.0 (#92105) 2024-08-21 11:40:42 -04:00
frontend_metrics.go Chore: Move ReqContext to contexthandler service (#62102) 2023-01-27 08:50:36 +01:00
frontendsettings_test.go Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
frontendsettings.go Auth: Passwordless Login Option Using Magic Links (#95436) 2024-11-14 08:50:55 -05:00
grafana_com_proxy.go API: don't re-add /api suffix to grafana.com API URL (#62280) 2023-01-27 10:20:55 +01:00
health_test.go HealthCheck: show enterprise commit (#75242) 2023-09-22 08:17:10 -03:00
health.go Chore: Remove Store interface and use db.DB instead (#60160) 2022-12-13 11:03:36 +01:00
http_server_test.go Grafana: Adds support for PKCS1 encrypted certs (#93451) 2024-09-19 15:03:06 -03:00
http_server.go wire up unified search from the ui; add basic search support (#94358) 2024-10-08 13:09:56 -04:00
index.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
login_oauth_test.go Auth: Remove auth broker flag and clean up login handlers (#73109) 2023-08-10 09:56:04 +02:00
login_oauth.go Auth: Fix redirection when auto_login is enabled (#94311) 2024-10-07 14:59:00 +02:00
login_test.go Auth: Introduce authn.SSOClientConfig to get client config from SSOSettings service (#94618) 2024-10-16 16:27:44 +02:00
login.go Auth: Passwordless Login Option Using Magic Links (#95436) 2024-11-14 08:50:55 -05:00
org_invite_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
org_invite.go User: Check SignedInUser OrgID in RevokeInvite (#95476) 2024-10-28 13:20:17 +01:00
org_test.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
org_users_test.go Revert read replica POC (#93551) 2024-09-25 15:21:39 -08:00
org_users.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
org.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
password.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00
playlist.go Playlist: Migrate to App SDK (#95691) 2024-11-04 14:18:49 -05:00
plugin_checks_test.go Plugins: Avoid returning 404 for AutoEnabled apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_checks.go Plugins: Avoid returning 404 for AutoEnabled apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_dashboards_test.go Chore: Evaluate if an app is disabled for API requests (#79564) 2023-12-15 16:37:39 +01:00
plugin_dashboards.go Auth: Unfurl OrgID in pkg/api to allow using identity.Requester interface (#76108) 2023-10-06 11:34:36 +02:00
plugin_metrics_test.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_metrics.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_proxy_test.go Plugins: Preserve trailing slash in plugin proxy (#86859) 2024-06-05 13:36:14 +02:00
plugin_proxy.go RBAC: Cover plugin routes (#80578) 2024-01-17 16:32:23 +01:00
plugin_resource_test.go Zipkin: Run health check through backend (#96031) 2024-11-07 16:48:00 +01:00
plugin_resource.go Plugins: Fix colon in CallResource URL returning an error when creating plugin resource request (#79746) 2024-01-29 10:31:49 +01:00
plugins_test.go Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
plugins.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
preferences_test.go Identity: Unfurl UserID and Email in pkg/api to user identity.Requester (#76112) 2023-10-09 16:07:28 +02:00
preferences.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
quota_test.go Add auth spans and remove deduplication code for scopes (#89804) 2024-07-02 22:08:57 -08:00
quota.go chore: add tracing to quote API and service methods with contexts (#92211) 2024-08-21 13:24:45 -04:00
README.md Chore: Fix Swagger/OpenAPI instructions (#86541) 2024-04-19 09:16:38 +03:00
render.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
search.go chore(tracing): add tracing for frontend and db session (#91509) 2024-08-05 17:17:39 -08:00
short_url_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
short_url.go Chore: Remove public vars in setting package (#81018) 2024-01-23 12:36:22 +01:00
signup.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
swagger_responses.go API keys: Return 410 Gone status from POST /auth/keys endpoint (#92965) 2024-09-05 13:10:24 +03:00
swagger_tags.json Browse Dashboards: Update docs to remove reference to General folder (#74528) 2023-09-08 03:57:16 +01:00
swagger.go Swagger: Add a custom swagger/api page (#91785) 2024-08-14 09:03:00 +03:00
user_test.go Zanzana: Evaluate permissions alongside with RBAC engine (#90064) 2024-07-05 11:31:23 +02:00
user_token_test.go AuthToken: Remove client token rotation feature toggle (#82886) 2024-02-16 15:03:37 +01:00
user_token.go Session Refactor: Add auth module label to session's list (#94958) 2024-10-22 10:57:36 +02:00
user.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
utils.go chore(tracing): add tracing for frontend and db session (#91509) 2024-08-05 17:17:39 -08:00

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2