grafana/pkg/api
Karl Persson 895222725c
Session: set authID and authenticatedBy (#85806)
* Authn: Resolve authenticate by and auth id when fethcing signed in user

* Change logout client interface to only take Requester interface

* Session: Fetch external auth info when authenticating sessions

* Use authenticated by from identity

* Move call to get auth-info into session client and use GetAuthenticatedBy in various places
2024-04-11 10:25:29 +02:00
..
apierrors Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
avatar
datasource
dtos AzureMonitor: User authentication support (#81918) 2024-03-19 16:32:24 +00:00
frontendlogging
pluginproxy Auth: Extended JWT client for OBO and Service Authentication (#83814) 2024-04-02 17:45:15 +02:00
response Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
routing Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
static
webassets
README.md
accesscontrol.go Misc: Remove unused params and impossible logic (#83756) 2024-03-01 12:08:00 +01:00
admin.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
admin_encryption.go
admin_provisioning.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_provisioning_test.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_test.go
admin_users.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
admin_users_test.go JWT Authentication: Add support for specifying groups in auth.jwt for teamsync (#82175) 2024-02-09 16:35:58 +01:00
alerting.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
annotations.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
annotations_test.go
api.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
api_test.go Chore: Update test database initialization (#81673) 2024-02-09 09:35:39 -05:00
apikey.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
basic_auth.go
basic_auth_test.go
common_test.go
dashboard.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
dashboard_permission.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
dashboard_permission_test.go
dashboard_snapshot.go Snapshots: Viewers can not create a Snapshot (#84952) 2024-03-22 14:31:01 -03:00
dashboard_snapshot_test.go
dashboard_test.go Add FolderUID for library elements (#83819) 2024-04-09 12:27:43 +02:00
dataproxy.go
datasources.go Misc: Remove unused params and impossible logic (#83756) 2024-03-01 12:08:00 +01:00
datasources_test.go Datasources: Remove unused functions (#85473) 2024-04-02 16:19:52 +02:00
fakes.go Plugins: Make it possible to support multiple plugin versions (#82116) 2024-02-12 12:47:49 +01:00
folder.go Folders: Allow listing folders with write permission (#83527) 2024-03-15 14:05:27 +02:00
folder_bench_test.go Chore: Replace sqlstore with db interface (#85366) 2024-04-04 15:04:47 +02:00
folder_permission.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
folder_permission_test.go
folder_test.go
frontend_logging.go
frontend_logging_test.go
frontend_metrics.go
frontendsettings.go Cloud migrations: create endpoint to create an access token (#84690) 2024-03-25 12:43:28 -03:00
frontendsettings_test.go Plugins: Refactor plugin config into separate env var and request scoped services (#83261) 2024-02-27 12:38:02 +01:00
grafana_com_proxy.go
health.go
health_test.go
http_server.go Chore: Replace sqlstore with db interface (#85366) 2024-04-04 15:04:47 +02:00
http_server_test.go Server: Reload TLS certs without a server restart (#83589) 2024-03-22 17:13:22 +02:00
index.go Session: set authID and authenticatedBy (#85806) 2024-04-11 10:25:29 +02:00
login.go Session: set authID and authenticatedBy (#85806) 2024-04-11 10:25:29 +02:00
login_oauth.go
login_oauth_test.go
login_test.go Session: set authID and authenticatedBy (#85806) 2024-04-11 10:25:29 +02:00
metrics.go
metrics_test.go Plugins: Tidy config struct (#84168) 2024-03-11 16:28:46 +01:00
org.go
org_invite.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
org_invite_test.go
org_test.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
org_users.go Authn: Add function to resolve identity from org and namespace id (#84555) 2024-03-15 15:08:15 +01:00
org_users_test.go Chore: Replace sqlstore with db interface (#85366) 2024-04-04 15:04:47 +02:00
password.go Password policy (#82268) 2024-02-16 04:58:05 -06:00
playlist.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
plugin_checks.go
plugin_checks_test.go
plugin_dashboards.go
plugin_dashboards_test.go
plugin_metrics.go
plugin_metrics_test.go
plugin_proxy.go
plugin_proxy_test.go
plugin_resource.go
plugin_resource_test.go Feature Flags: use FeatureToggles interface where possible (#85131) 2024-04-04 12:22:31 -04:00
plugins.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
plugins_test.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
preferences.go
preferences_test.go
quota.go
quota_test.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
render.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
search.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
short_url.go
short_url_test.go
signup.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
swagger.go
swagger_responses.go
swagger_tags.json
user.go Email: trigger email verification flow (#85587) 2024-04-05 12:05:46 +02:00
user_test.go Email: trigger email verification flow (#85587) 2024-04-05 12:05:46 +02:00
user_token.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
user_token_test.go AuthToken: Remove client token rotation feature toggle (#82886) 2024-02-16 15:03:37 +01:00
utils.go

README.md

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get swagger