mirror of
https://gitverse.ru/kpa39l/monitoring.git
synced 2026-09-29 09:55:09 +00:00
OpenSpec: разнести openspec по проектам
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# grafana-access-control Specification
|
||||
|
||||
## Purpose
|
||||
TBD - created by archiving change grafana-readonly-user. Update Purpose after archive.
|
||||
|
||||
## Requirements
|
||||
|
||||
### Requirement: Read-only Grafana user for Vinogorod IT
|
||||
|
||||
Grafana MUST provide a read-only account for the Vinogorod IT department:
|
||||
login `it@vinogorod.ru`, role `Viewer`, in the default organization (orgId 1).
|
||||
The account MUST NOT be able to create, edit, or delete dashboards,
|
||||
datasources, or settings.
|
||||
|
||||
#### Scenario: User exists with Viewer role
|
||||
- GIVEN the admin has created the user `it@vinogorod.ru` in the Grafana UI
|
||||
- WHEN the user logs in with the shared password
|
||||
- THEN authentication succeeds (Basic auth `/api/user` → HTTP 200)
|
||||
- AND the organization role is `Viewer` (`/api/orgs/1/users` → role "Viewer")
|
||||
|
||||
#### Scenario: Unknown credentials rejected
|
||||
- GIVEN the read-only user `it@vinogorod.ru`
|
||||
- WHEN a request is made with a wrong password
|
||||
- THEN the API returns HTTP 401
|
||||
|
||||
#### Scenario: Read-only enforced
|
||||
- GIVEN the user `it@vinogorod.ru` is logged in as `Viewer`
|
||||
- WHEN the user attempts a privileged operation (e.g. `POST /api/users`,
|
||||
modify datasources)
|
||||
- THEN the request is rejected (HTTP 403/404)
|
||||
|
||||
### Requirement: No admin rights for IT user
|
||||
|
||||
The IT read-only account MUST NOT have admin or editor rights; only viewing
|
||||
of dashboards and logs is permitted.
|
||||
|
||||
#### Scenario: Role is not elevated
|
||||
- GIVEN the user `it@vinogorod.ru`
|
||||
- WHEN checking its org role and admin flag (`/api/user` + `/api/orgs/1/users`)
|
||||
- THEN role is `Viewer` and `isGrafanaAdmin` is false
|
||||
Reference in New Issue
Block a user