grafana/pkg/api
Ieva 105313f5c2
RBAC: Adding action set resolver for RBAC evaluation (#86801)
* add action set resolver

* rename variables

* some fixes and some tests

* more tests

* more tests, and put action set storing behind a feature toggle

* undo change from cfg to feature mgmt - will cover it in a separate PR due to the amount of test changes

* fix dependency cycle, update some tests

* add one more test

* fix for feature toggle check not being set on test configs

* linting fixes

* check that action set name can be split nicely

* clean up tests by turning GetActionSetNames into a function

* undo accidental change

* test fix

* more test fixes
2024-05-09 10:18:03 +01:00
..
apierrors Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
avatar Chore: Remove public vars in setting package (#81018) 2024-01-23 12:36:22 +01:00
datasource mssql: prepare logs-handling for decouple-datasource changes (#79214) 2023-12-11 09:14:06 +01:00
dtos Azure: get custom cloud list from grafana-azure-sdk-go package (#86717) 2024-05-04 13:17:51 +03:00
frontendlogging Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
pluginproxy Revert #86466 (#87405) 2024-05-06 14:40:32 -05:00
response Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
routing Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
static
webassets Frontend: Reload the browser when backend configuration/assets change (#79057) 2024-01-04 08:00:07 +01:00
README.md Chore: Fix Swagger/OpenAPI instructions (#86541) 2024-04-19 09:16:38 +03:00
accesscontrol.go Misc: Remove unused params and impossible logic (#83756) 2024-03-01 12:08:00 +01:00
admin.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
admin_encryption.go Config: Add configuration option to define custom user-facing general error message for certain error types (#70023) 2023-06-16 10:46:47 -05:00
admin_provisioning.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_provisioning_test.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_test.go Auth: Add anonymous users view and stats (#78685) 2023-11-29 17:58:41 +01:00
admin_users.go Identity: Use typed version of namespace id (#87257) 2024-05-08 14:03:53 +02:00
admin_users_test.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00
alerting.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
annotations.go Identity: Use typed version of namespace id (#87257) 2024-05-08 14:03:53 +02:00
annotations_test.go Annotations: Remove dashboard permission checks for annotations (#78352) 2023-11-23 10:47:37 +00:00
api.go Feature toggles: Remove dashboardEmbed toggle (#86587) 2024-04-19 12:48:08 +02:00
api_test.go Chore: Update test database initialization (#81673) 2024-02-09 09:35:39 -05:00
apikey.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
basic_auth.go
basic_auth_test.go
common_test.go FeatureFlags: Use interface rather than manager (#80000) 2024-01-09 10:38:06 -08:00
dashboard.go Chore: Fix error handling in postDashboard, remove UserDisplayDTO, fix live redis client initialization (#87206) 2024-05-06 14:17:34 -04:00
dashboard_permission.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
dashboard_permission_test.go authz: Clean up acl endpoints and dashboard guardian (#73746) 2023-08-24 15:37:54 +02:00
dashboard_snapshot.go Snapshots: Viewers can not create a Snapshot (#84952) 2024-03-22 14:31:01 -03:00
dashboard_snapshot_test.go K8s/Snapshots: Add dashboardsnapshot api group (#77667) 2024-02-01 22:40:11 -08:00
dashboard_test.go Chore: Remove cfg from folder service (#87212) 2024-05-02 13:18:54 +02:00
dataproxy.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
datasources.go Misc: Remove unused params and impossible logic (#83756) 2024-03-01 12:08:00 +01:00
datasources_test.go Datasources: Remove unused functions (#85473) 2024-04-02 16:19:52 +02:00
ds_query.go QueryService: Add feature toggles to better support testing (#86493) 2024-04-19 12:26:21 +03:00
ds_query_test.go QueryService: Add feature toggles to better support testing (#86493) 2024-04-19 12:26:21 +03:00
fakes.go Plugins: Make it possible to support multiple plugin versions (#82116) 2024-02-12 12:47:49 +01:00
folder.go Folders: Allow listing folders with write permission (#83527) 2024-03-15 14:05:27 +02:00
folder_bench_test.go RBAC: Adding action set resolver for RBAC evaluation (#86801) 2024-05-09 10:18:03 +01:00
folder_permission.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
folder_permission_test.go Remove deprecated FolderID from api tests (#79466) 2023-12-20 15:12:05 +01:00
folder_test.go FeatureFlags: Use interface rather than manager (#80000) 2024-01-09 10:38:06 -08:00
frontend_logging.go Plugins: Add context to StaticRouteResolver and ErrorResolver interfaces (#73121) 2023-08-10 10:32:12 +02:00
frontend_logging_test.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
frontend_metrics.go Chore: Move ReqContext to contexthandler service (#62102) 2023-01-27 08:50:36 +01:00
frontendsettings.go Azure: get custom cloud list from grafana-azure-sdk-go package (#86717) 2024-05-04 13:17:51 +03:00
frontendsettings_test.go Auth: Add `IsClientEnabled` and `IsEnabled` for the `authn.Service` and `authn.Client` interfaces (#86034) 2024-04-15 10:54:50 +02:00
grafana_com_proxy.go API: don't re-add /api suffix to grafana.com API URL (#62280) 2023-01-27 10:20:55 +01:00
health.go Chore: Remove Store interface and use db.DB instead (#60160) 2022-12-13 11:03:36 +01:00
health_test.go HealthCheck: show enterprise commit (#75242) 2023-09-22 08:17:10 -03:00
http_server.go Chore: Replace sqlstore with db interface (#85366) 2024-04-04 15:04:47 +02:00
http_server_test.go Server: Reload TLS certs without a server restart (#83589) 2024-03-22 17:13:22 +02:00
index.go Session: set authID and authenticatedBy (#85806) 2024-04-11 10:25:29 +02:00
login.go Auth: Add `IsClientEnabled` and `IsEnabled` for the `authn.Service` and `authn.Client` interfaces (#86034) 2024-04-15 10:54:50 +02:00
login_oauth.go Auth: Remove unused Authenticator service (#73143) 2023-08-10 11:02:32 +02:00
login_oauth_test.go Auth: Remove auth broker flag and clean up login handlers (#73109) 2023-08-10 09:56:04 +02:00
login_test.go AuthN: Use typed namespace id inside authn package (#86048) 2024-04-24 09:57:34 +02:00
org.go Chore: Port user services to identity.Requester (#73851) 2023-08-28 10:42:24 +02:00
org_invite.go Chore: Fix error handling in postDashboard, remove UserDisplayDTO, fix live redis client initialization (#87206) 2024-05-06 14:17:34 -04:00
org_invite_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
org_test.go AuthN: Use typed namespace id inside authn package (#86048) 2024-04-24 09:57:34 +02:00
org_users.go Authn: Add function to resolve identity from org and namespace id (#84555) 2024-03-15 15:08:15 +01:00
org_users_test.go User: Add tracing (#87028) 2024-04-30 13:15:56 +02:00
password.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00
playlist.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
plugin_checks.go Chore: Evaluate if an app is disabled for API requests (#79564) 2023-12-15 16:37:39 +01:00
plugin_checks_test.go Chore: Evaluate if an app is disabled for API requests (#79564) 2023-12-15 16:37:39 +01:00
plugin_dashboards.go Auth: Unfurl OrgID in pkg/api to allow using identity.Requester interface (#76108) 2023-10-06 11:34:36 +02:00
plugin_dashboards_test.go Chore: Evaluate if an app is disabled for API requests (#79564) 2023-12-15 16:37:39 +01:00
plugin_metrics.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_metrics_test.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_proxy.go RBAC: Cover plugin routes (#80578) 2024-01-17 16:32:23 +01:00
plugin_proxy_test.go
plugin_resource.go Plugins: Fix colon in CallResource URL returning an error when creating plugin resource request (#79746) 2024-01-29 10:31:49 +01:00
plugin_resource_test.go Feature Flags: use FeatureToggles interface where possible (#85131) 2024-04-04 12:22:31 -04:00
plugins.go Return plugin error when requesting settings (#86052) 2024-04-18 14:29:02 +02:00
plugins_test.go Return plugin error when requesting settings (#86052) 2024-04-18 14:29:02 +02:00
preferences.go Teams: Move team API to own service (#76347) 2023-10-12 10:10:54 +02:00
preferences_test.go Identity: Unfurl UserID and Email in pkg/api to user identity.Requester (#76112) 2023-10-09 16:07:28 +02:00
quota.go Auth: Unfurl OrgID in pkg/api to allow using identity.Requester interface (#76108) 2023-10-06 11:34:36 +02:00
quota_test.go Access control: Use ResolveIdentity() for authorizing in org (#85549) 2024-04-10 12:42:13 +02:00
render.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
search.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
short_url.go Chore: Remove public vars in setting package (#81018) 2024-01-23 12:36:22 +01:00
short_url_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
signup.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00
swagger.go Swagger: Show k8s APIs (#78091) 2023-11-15 06:42:35 -08:00
swagger_responses.go PublicDashboards: Add swagger documentation (#75318) 2023-10-30 10:32:07 -03:00
swagger_tags.json Browse Dashboards: Update docs to remove reference to `General` folder (#74528) 2023-09-08 03:57:16 +01:00
user.go Chore: Fix error handling in postDashboard, remove UserDisplayDTO, fix live redis client initialization (#87206) 2024-05-06 14:17:34 -04:00
user_test.go User: Add tracing (#87028) 2024-04-30 13:15:56 +02:00
user_token.go Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
user_token_test.go AuthToken: Remove client token rotation feature toggle (#82886) 2024-02-16 15:03:37 +01:00
utils.go User: use update function for password updates (#86419) 2024-04-17 15:24:36 +02:00

README.md

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2