mirror of
https://gitverse.ru/kpa39l/monitoring.git
synced 2026-09-29 09:55:09 +00:00
1.5 KiB
1.5 KiB
grafana-access-control Specification
Purpose
TBD - created by archiving change grafana-readonly-user. Update Purpose after archive.
Requirements
Requirement: Read-only Grafana user for Vinogorod IT
Grafana MUST provide a read-only account for the Vinogorod IT department:
login it@vinogorod.ru, role Viewer, in the default organization (orgId 1).
The account MUST NOT be able to create, edit, or delete dashboards,
datasources, or settings.
Scenario: User exists with Viewer role
- GIVEN the admin has created the user
it@vinogorod.ruin the Grafana UI - WHEN the user logs in with the shared password
- THEN authentication succeeds (Basic auth
/api/user→ HTTP 200) - AND the organization role is
Viewer(/api/orgs/1/users→ role "Viewer")
Scenario: Unknown credentials rejected
- GIVEN the read-only user
it@vinogorod.ru - WHEN a request is made with a wrong password
- THEN the API returns HTTP 401
Scenario: Read-only enforced
- GIVEN the user
it@vinogorod.ruis logged in asViewer - WHEN the user attempts a privileged operation (e.g.
POST /api/users, modify datasources) - THEN the request is rejected (HTTP 403/404)
Requirement: No admin rights for IT user
The IT read-only account MUST NOT have admin or editor rights; only viewing of dashboards and logs is permitted.
Scenario: Role is not elevated
- GIVEN the user
it@vinogorod.ru - WHEN checking its org role and admin flag (
/api/user+/api/orgs/1/users) - THEN role is
ViewerandisGrafanaAdminis false