mirror of
https://gitverse.ru/kpa39l/monitoring.git
synced 2026-09-29 09:55:09 +00:00
41 lines
1.5 KiB
Markdown
41 lines
1.5 KiB
Markdown
# grafana-access-control Specification
|
|
|
|
## Purpose
|
|
TBD - created by archiving change grafana-readonly-user. Update Purpose after archive.
|
|
|
|
## Requirements
|
|
|
|
### Requirement: Read-only Grafana user for Vinogorod IT
|
|
|
|
Grafana MUST provide a read-only account for the Vinogorod IT department:
|
|
login `it@vinogorod.ru`, role `Viewer`, in the default organization (orgId 1).
|
|
The account MUST NOT be able to create, edit, or delete dashboards,
|
|
datasources, or settings.
|
|
|
|
#### Scenario: User exists with Viewer role
|
|
- GIVEN the admin has created the user `it@vinogorod.ru` in the Grafana UI
|
|
- WHEN the user logs in with the shared password
|
|
- THEN authentication succeeds (Basic auth `/api/user` → HTTP 200)
|
|
- AND the organization role is `Viewer` (`/api/orgs/1/users` → role "Viewer")
|
|
|
|
#### Scenario: Unknown credentials rejected
|
|
- GIVEN the read-only user `it@vinogorod.ru`
|
|
- WHEN a request is made with a wrong password
|
|
- THEN the API returns HTTP 401
|
|
|
|
#### Scenario: Read-only enforced
|
|
- GIVEN the user `it@vinogorod.ru` is logged in as `Viewer`
|
|
- WHEN the user attempts a privileged operation (e.g. `POST /api/users`,
|
|
modify datasources)
|
|
- THEN the request is rejected (HTTP 403/404)
|
|
|
|
### Requirement: No admin rights for IT user
|
|
|
|
The IT read-only account MUST NOT have admin or editor rights; only viewing
|
|
of dashboards and logs is permitted.
|
|
|
|
#### Scenario: Role is not elevated
|
|
- GIVEN the user `it@vinogorod.ru`
|
|
- WHEN checking its org role and admin flag (`/api/user` + `/api/orgs/1/users`)
|
|
- THEN role is `Viewer` and `isGrafanaAdmin` is false
|