Files

1.5 KiB

grafana-access-control Specification

Purpose

TBD - created by archiving change grafana-readonly-user. Update Purpose after archive.

Requirements

Requirement: Read-only Grafana user for Vinogorod IT

Grafana MUST provide a read-only account for the Vinogorod IT department: login it@vinogorod.ru, role Viewer, in the default organization (orgId 1). The account MUST NOT be able to create, edit, or delete dashboards, datasources, or settings.

Scenario: User exists with Viewer role

  • GIVEN the admin has created the user it@vinogorod.ru in the Grafana UI
  • WHEN the user logs in with the shared password
  • THEN authentication succeeds (Basic auth /api/user → HTTP 200)
  • AND the organization role is Viewer (/api/orgs/1/users → role "Viewer")

Scenario: Unknown credentials rejected

  • GIVEN the read-only user it@vinogorod.ru
  • WHEN a request is made with a wrong password
  • THEN the API returns HTTP 401

Scenario: Read-only enforced

  • GIVEN the user it@vinogorod.ru is logged in as Viewer
  • WHEN the user attempts a privileged operation (e.g. POST /api/users, modify datasources)
  • THEN the request is rejected (HTTP 403/404)

Requirement: No admin rights for IT user

The IT read-only account MUST NOT have admin or editor rights; only viewing of dashboards and logs is permitted.

Scenario: Role is not elevated

  • GIVEN the user it@vinogorod.ru
  • WHEN checking its org role and admin flag (/api/user + /api/orgs/1/users)
  • THEN role is Viewer and isGrafanaAdmin is false