grafana/pkg/api
grafana-delivery-bot[bot] 26b81feb85
[release-12.0.1] Apply security patch 357-202503311017.patch (#104493)
Apply security patch 357-202503311017.patch (#104490)

* Sanitize paths before evaluating access to route

* use util.CleanRelativePath

---------

Co-authored-by: Andres Martinez Gotor <andres.martinez@grafana.com>
(cherry picked from commit 1f707d16ed)

Co-authored-by: Yuri Tseretyan <yuriy.tseretyan@grafana.com>
2025-04-24 20:40:18 +01:00
..
apierrors K8s: Fix error conversion for provisioned dashboards (#103074) 2025-03-31 14:34:54 +01:00
avatar
datasource Prometheus: Add support for cloud partners Prometheus data sources (#103482) 2025-04-10 12:49:11 -07:00
dtos [release-12.0.1] K8s: Dashboards: Mark as v1beta1 (#104422) 2025-04-23 19:21:59 +01:00
frontendlogging
pluginproxy [release-12.0.1] Apply security patch 357-202503311017.patch (#104493) 2025-04-24 20:40:18 +01:00
response
routing
static
webassets Frontend: Extract CSS imports into files (#94655) 2024-10-16 11:10:34 +02:00
README.md Swagger: Fix sync issue with enterprise (#97696) 2024-12-09 21:21:22 +02:00
accesscontrol.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin_encryption.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
admin_provisioning.go
admin_provisioning_test.go
admin_test.go
admin_users.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin_users_test.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
alerting.go
annotations.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
annotations_test.go Annotations: Fix annotations scope resolver (#102612) 2025-03-24 16:00:07 +01:00
api.go Dashboard Restore: Remove experimental functionality under feature flag `dashboardRestore` for now - this will be reworked (#103204) 2025-04-03 02:52:54 -05:00
api_test.go
apikey.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
basic_auth.go
basic_auth_test.go
common_test.go K8s: refactor build handler chain func to allow easier injection from enterprise (#100777) 2025-02-15 04:08:00 +02:00
dashboard.go [release-12.0.1] K8s: Dashboards: Mark as v1beta1 (#104422) 2025-04-23 19:21:59 +01:00
dashboard_permission.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
dashboard_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_snapshot.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
dashboard_snapshot_test.go RBAC: Remove dashboard guardians pt 3 (#102558) 2025-03-21 10:44:16 +00:00
dashboard_test.go App Platform: Remove mutable globals (#102962) 2025-03-27 15:46:09 +01:00
dataproxy.go
datasources.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
datasources_test.go LBAC for datasources: GA (#99511) 2025-02-20 10:26:46 +00:00
ds_query.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
ds_query_test.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
fakes.go Preinstall: Allow to set a download URL (#96535) 2024-11-29 16:02:33 +01:00
folder.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
folder_bench_test.go App Platform: Remove mutable globals (#102962) 2025-03-27 15:46:09 +01:00
folder_permission.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
folder_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_test.go K8s/Folders: Use v1beta1 and app-sdk based spec (#103975) 2025-04-14 23:20:10 +03:00
frontend_logging.go
frontend_logging_test.go
frontend_metrics.go
frontendsettings.go Dashboards: Add a config setting that limits the number of series that will be displayed in a panel. Users can opt in to render all series. (#103405) 2025-04-11 13:56:58 +02:00
frontendsettings_test.go i18n: wires up translations for plugins (#102853) 2025-03-31 06:38:38 +02:00
grafana_com_proxy.go Plugins: Use grafana-com sso_api_token (#97096) 2024-12-02 16:04:05 +01:00
health.go Spanner-related fixes (#102376) 2025-03-19 12:34:44 +01:00
health_test.go Auth: Separate anonymous settings to its own struct (#97791) 2024-12-13 10:46:27 +01:00
http_server.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
http_server_test.go Grafana: Adds support for PKCS1 encrypted certs (#93451) 2024-09-19 15:03:06 -03:00
index.go i18n: Update `internationalization/dates.ts` to use `locale` (#103731) 2025-04-11 11:24:40 +02:00
login.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
login_oauth.go Auth: Fix redirection when auto_login is enabled (#94311) 2024-10-07 14:59:00 +02:00
login_oauth_test.go
login_test.go Authlib: Use types package rather than claims (#99243) 2025-01-21 12:06:55 +03:00
org.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_invite.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_invite_test.go
org_test.go Authlib: Use types package rather than claims (#99243) 2025-01-21 12:06:55 +03:00
org_users.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_users_test.go IDToken: cache invalidation (#100592) 2025-02-13 14:10:58 +01:00
password.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
playlist.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_checks.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_checks_test.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_dashboards.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_dashboards_test.go
plugin_metrics.go
plugin_metrics_test.go
plugin_proxy.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_proxy_test.go
plugin_resource.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_resource_test.go Jaeger: run health check through backend (#99322) 2025-01-24 19:37:36 +07:00
plugins.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugins_test.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
preferences.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
preferences_test.go
quota.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
quota_test.go
render.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
search.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
short_url.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
short_url_test.go
signup.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
swagger.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
swagger_responses.go K8s: Schema v2: Return 406 in /api (#101842) 2025-03-07 18:20:02 -06:00
swagger_tags.json
user.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
user_test.go Return correct disabled status when looking up a user (#103182) 2025-04-02 13:38:10 +02:00
user_token.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
user_token_test.go
utils.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00

README.md

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).

For enterprise endpoints make sure you add the enterprise tag as well.


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2