2022-12-17 00:09:06 +08:00
|
|
|
package db
|
2018-02-08 00:54:21 +08:00
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
|
2022-08-10 16:32:03 +08:00
|
|
|
ac "github.com/grafana/grafana/pkg/services/accesscontrol"
|
2023-01-26 21:46:30 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/dashboards"
|
2023-04-06 16:16:15 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
2022-12-17 00:09:06 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/sqlstore/migrator"
|
2022-08-10 16:32:03 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/sqlstore/permissions"
|
2022-08-10 17:56:48 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/user"
|
2022-08-10 16:32:03 +08:00
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
2018-02-08 00:54:21 +08:00
|
|
|
)
|
|
|
|
|
2023-04-06 16:16:15 +08:00
|
|
|
func NewSqlBuilder(cfg *setting.Cfg, features featuremgmt.FeatureToggles, dialect migrator.Dialect, recursiveQueriesAreSupported bool) SQLBuilder {
|
|
|
|
return SQLBuilder{cfg: cfg, features: features, dialect: dialect, recursiveQueriesAreSupported: recursiveQueriesAreSupported}
|
2022-08-10 16:32:03 +08:00
|
|
|
}
|
|
|
|
|
2020-11-11 13:21:08 +08:00
|
|
|
type SQLBuilder struct {
|
2023-04-06 16:16:15 +08:00
|
|
|
cfg *setting.Cfg
|
|
|
|
features featuremgmt.FeatureToggles
|
|
|
|
sql bytes.Buffer
|
|
|
|
params []interface{}
|
|
|
|
recQry string
|
|
|
|
recQryParams []interface{}
|
|
|
|
recursiveQueriesAreSupported bool
|
|
|
|
|
2022-12-17 00:09:06 +08:00
|
|
|
dialect migrator.Dialect
|
2018-02-08 00:54:21 +08:00
|
|
|
}
|
|
|
|
|
2020-11-11 13:21:08 +08:00
|
|
|
func (sb *SQLBuilder) Write(sql string, params ...interface{}) {
|
2018-02-16 20:56:04 +08:00
|
|
|
sb.sql.WriteString(sql)
|
|
|
|
|
|
|
|
if len(params) > 0 {
|
|
|
|
sb.params = append(sb.params, params...)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-11-11 13:21:08 +08:00
|
|
|
func (sb *SQLBuilder) GetSQLString() string {
|
2023-04-06 16:16:15 +08:00
|
|
|
if sb.recQry == "" {
|
|
|
|
return sb.sql.String()
|
|
|
|
}
|
|
|
|
|
|
|
|
var bf bytes.Buffer
|
|
|
|
bf.WriteString(sb.recQry)
|
|
|
|
bf.WriteString(sb.sql.String())
|
|
|
|
return bf.String()
|
2018-02-16 20:56:04 +08:00
|
|
|
}
|
|
|
|
|
2021-02-24 21:06:22 +08:00
|
|
|
func (sb *SQLBuilder) GetParams() []interface{} {
|
2023-04-06 16:16:15 +08:00
|
|
|
if len(sb.recQryParams) == 0 {
|
|
|
|
return sb.params
|
|
|
|
}
|
|
|
|
|
|
|
|
sb.params = append(sb.recQryParams, sb.params...)
|
2021-02-24 21:06:22 +08:00
|
|
|
return sb.params
|
|
|
|
}
|
|
|
|
|
2020-11-11 13:21:08 +08:00
|
|
|
func (sb *SQLBuilder) AddParams(params ...interface{}) {
|
2018-02-16 20:56:04 +08:00
|
|
|
sb.params = append(sb.params, params...)
|
|
|
|
}
|
|
|
|
|
2023-06-21 21:48:09 +08:00
|
|
|
func (sb *SQLBuilder) WriteDashboardPermissionFilter(user *user.SignedInUser, permission dashboards.PermissionType, queryType string) {
|
2022-08-10 16:32:03 +08:00
|
|
|
var (
|
2023-04-06 16:16:15 +08:00
|
|
|
sql string
|
|
|
|
params []interface{}
|
|
|
|
recQry string
|
|
|
|
recQryParams []interface{}
|
2022-08-10 16:32:03 +08:00
|
|
|
)
|
|
|
|
if !ac.IsDisabled(sb.cfg) {
|
2023-06-21 21:48:09 +08:00
|
|
|
filterRBAC := permissions.NewAccessControlDashboardPermissionFilter(user, permission, queryType, sb.features, sb.recursiveQueriesAreSupported)
|
2023-04-06 16:16:15 +08:00
|
|
|
sql, params = filterRBAC.Where()
|
|
|
|
recQry, recQryParams = filterRBAC.With()
|
2022-08-10 16:32:03 +08:00
|
|
|
} else {
|
|
|
|
sql, params = permissions.DashboardPermissionFilter{
|
|
|
|
OrgRole: user.OrgRole,
|
2022-12-17 00:09:06 +08:00
|
|
|
Dialect: sb.dialect,
|
2022-08-11 19:28:55 +08:00
|
|
|
UserId: user.UserID,
|
|
|
|
OrgId: user.OrgID,
|
2022-08-10 16:32:03 +08:00
|
|
|
PermissionLevel: permission,
|
|
|
|
}.Where()
|
2018-02-08 00:54:21 +08:00
|
|
|
}
|
|
|
|
|
2022-08-10 16:32:03 +08:00
|
|
|
sb.sql.WriteString(" AND " + sql)
|
|
|
|
sb.params = append(sb.params, params...)
|
2023-04-06 16:16:15 +08:00
|
|
|
sb.recQry = recQry
|
|
|
|
sb.recQryParams = recQryParams
|
2018-02-08 00:54:21 +08:00
|
|
|
}
|