grafana/pkg/api
Jev Forsberg 988d964200
Backend Unit Tests / Grafana (push) Has been cancelled Details
Backend Unit Tests / Grafana Enterprise (push) Has been cancelled Details
CodeQL checks / Analyze (go) (push) Has been cancelled Details
CodeQL checks / Analyze (javascript) (push) Has been cancelled Details
CodeQL checks / Analyze (python) (push) Has been cancelled Details
Lint Frontend / Verify i18n (push) Has been cancelled Details
Lint Frontend / Lint (push) Has been cancelled Details
Lint Frontend / Typecheck (push) Has been cancelled Details
Lint Frontend / Betterer (push) Has been cancelled Details
End-to-end tests / Build & Package Grafana (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (1) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (2) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (3) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (4) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (5) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (6) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (7) (push) Has been cancelled Details
Frontend tests / Unit tests (${{ matrix.chunk }} / 8) (8) (push) Has been cancelled Details
Integration Tests / Sqlite (push) Has been cancelled Details
Integration Tests / MySQL (push) Has been cancelled Details
Integration Tests / Postgres (push) Has been cancelled Details
Dispatch sync to mirror / dispatch-job (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (dashboards-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (panels-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (smoke-tests-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (various-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (old arch) (old-arch/dashboards-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (old arch) (old-arch/panels-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (old arch) (old-arch/smoke-tests-suite) (push) Has been cancelled Details
End-to-end tests / ${{ matrix.suite }} (old arch) (old-arch/various-suite) (push) Has been cancelled Details
Security: Fixes for CVE-2025-6197 and CVE-2025-6023 (#108280)
fix(redirect): make validation of redirect uri stricter

Co-authored-by: volcanonoodle <114113189+volcanonoodle@users.noreply.github.com>
2025-07-17 15:06:45 -06:00
..
apierrors Dashboards: Remove unique name constraints (#90687) 2024-10-29 08:58:39 +03:00
avatar
datasource [release-11.5.4] Prometheus: Add support for cloud partners Prometheus data sources (#103942) 2025-04-14 09:47:18 -07:00
dtos Codegen: Remove pfs codegen dependency from Grafana codebase (#98840) 2025-01-10 22:43:40 +02:00
frontendlogging
pluginproxy apply security patch: release-11.5.4/365-202504020730.patch 2025-04-22 13:47:05 +00:00
response
routing
static [release-11.5.6]: Fix static tests (#106133) 2025-05-28 16:04:01 +03:00
webassets Frontend: Extract CSS imports into files (#94655) 2024-10-16 11:10:34 +02:00
README.md Swagger: Fix sync issue with enterprise (#97696) 2024-12-09 21:21:22 +02:00
accesscontrol.go Snapshots: Add RBAC roles for creating and deleting (#96126) 2024-11-26 09:13:17 -03:00
admin.go
admin_encryption.go
admin_provisioning.go
admin_provisioning_test.go
admin_test.go
admin_users.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
admin_users_test.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
alerting.go
annotations.go Ensure all internal Services are using FolderService and not FolderStore (#98370) 2024-12-30 13:48:35 -03:00
annotations_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
api.go CloudMigrations: Introduce RBAC role for migration assistant (#98588) 2025-01-09 06:03:42 +02:00
api_test.go
apikey.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
basic_auth.go
basic_auth_test.go
common_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
dashboard.go UserDisplay: Handle both service accounts and user names when resolving "createdBy" (#98719) 2025-01-10 10:06:59 +01:00
dashboard_permission.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_snapshot.go Snapshots: Add RBAC roles for creating and deleting (#96126) 2024-11-26 09:13:17 -03:00
dashboard_snapshot_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
dashboard_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
dataproxy.go
datasources.go [docs] document 409 Conflict on updating data sources. (#93170) 2024-11-21 11:28:30 +02:00
datasources_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
ds_query.go Plugins: Remove datasourceQueryMultiStatus feature toggle (#90191) 2024-07-10 11:15:10 +02:00
ds_query_test.go Instrument tracing across accesscontrol (#91864) 2024-08-16 14:08:19 -08:00
fakes.go Preinstall: Allow to set a download URL (#96535) 2024-11-29 16:02:33 +01:00
folder.go Filewalkwithme/unistore refactor folder service to hit folder apiserver (#98409) 2025-01-13 18:15:35 -03:00
folder_bench_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
folder_permission.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_test.go UserDisplay: Handle both service accounts and user names when resolving "createdBy" (#98719) 2025-01-10 10:06:59 +01:00
frontend_logging.go Chore: Bump Go to 1.23.0 (#92105) 2024-08-21 11:40:42 -04:00
frontend_logging_test.go
frontend_metrics.go
frontendsettings.go [release-11.5.4] Prometheus: Add support for cloud partners Prometheus data sources (#103942) 2025-04-14 09:47:18 -07:00
frontendsettings_test.go Auth: Separate anonymous settings to its own struct (#97791) 2024-12-13 10:46:27 +01:00
grafana_com_proxy.go Plugins: Use grafana-com sso_api_token (#97096) 2024-12-02 16:04:05 +01:00
health.go
health_test.go Auth: Separate anonymous settings to its own struct (#97791) 2024-12-13 10:46:27 +01:00
http_server.go Orgs: Remove dependency on dashboard table for deletion (#98501) 2025-01-06 19:05:22 +02:00
http_server_test.go Grafana: Adds support for PKCS1 encrypted certs (#93451) 2024-09-19 15:03:06 -03:00
index.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
login.go Security: Fixes for CVE-2025-6197 and CVE-2025-6023 (#108280) 2025-07-17 15:06:45 -06:00
login_oauth.go Auth: Fix redirection when auto_login is enabled (#94311) 2024-10-07 14:59:00 +02:00
login_oauth_test.go Security: Fixes for CVE-2025-6197 and CVE-2025-6023 (#108280) 2025-07-17 15:06:45 -06:00
login_test.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
org.go Orgs: Remove dependency on dashboard table for deletion (#98501) 2025-01-06 19:05:22 +02:00
org_invite.go Requester: Remove duplicated function (#97038) 2024-11-26 15:29:31 +01:00
org_invite_test.go
org_test.go Orgs: Remove dependency on dashboard table for deletion (#98501) 2025-01-06 19:05:22 +02:00
org_users.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
org_users_test.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
password.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
playlist.go Playlist: Migrate to App SDK (#95691) 2024-11-04 14:18:49 -05:00
plugin_checks.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_checks_test.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_dashboards.go
plugin_dashboards_test.go
plugin_metrics.go
plugin_metrics_test.go
plugin_proxy.go
plugin_proxy_test.go
plugin_resource.go
plugin_resource_test.go Zipkin: Run health check through backend (#96031) 2024-11-07 16:48:00 +01:00
plugins.go Codegen: Remove pfs codegen dependency from Grafana codebase (#98840) 2025-01-10 22:43:40 +02:00
plugins_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
preferences.go [release-11.5.7] IAM: Return 401 if identity type is not valid in GetUserPreferences (#107828) 2025-07-09 08:09:38 +01:00
preferences_test.go
quota.go chore: add tracing to quote API and service methods with contexts (#92211) 2024-08-21 13:24:45 -04:00
quota_test.go Add auth spans and remove deduplication code for scopes (#89804) 2024-07-02 22:08:57 -08:00
render.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
search.go chore(tracing): add tracing for frontend and db session (#91509) 2024-08-05 17:17:39 -08:00
short_url.go fix(short-url): redirect to main page if not found (#97347) 2024-12-03 16:32:53 +01:00
short_url_test.go
signup.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
swagger.go Swagger: Add a custom swagger/api page (#91785) 2024-08-14 09:03:00 +03:00
swagger_responses.go API keys: Return 410 Gone status from POST /auth/keys endpoint (#92965) 2024-09-05 13:10:24 +03:00
swagger_tags.json
user.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
user_test.go Zanzana: Remove usage from legacy access control (#98883) 2025-01-14 10:26:15 +01:00
user_token.go [release-11.5.4] [IAM] Prepend AppSubURL to redirectURI before validating it (#103771) 2025-04-11 14:00:33 +02:00
user_token_test.go Security: Fixes for CVE-2025-6197 and CVE-2025-6023 (#108280) 2025-07-17 15:06:45 -06:00
utils.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00

README.md

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).

For enterprise endpoints make sure you add the enterprise tag as well.


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2