mirror of
https://gitverse.ru/kpa39l/openspec-lab.git
synced 2026-09-29 09:15:01 +00:00
Archive grafana-readonly-user: read-only пользователь Grafana (it@vinogorod.ru, Viewer); OSS 11.1 provisioning users не работает — только UI
This commit is contained in:
+37
@@ -0,0 +1,37 @@
|
||||
# Delta for grafana access control
|
||||
|
||||
## ADDED Requirements
|
||||
|
||||
### Requirement: Read-only Grafana user for Vinogorod IT
|
||||
|
||||
Grafana MUST provide a read-only account for the Vinogorod IT department:
|
||||
login `it@vinogorod.ru`, role `Viewer`, in the default organization (orgId 1).
|
||||
The account MUST NOT be able to create, edit, or delete dashboards,
|
||||
datasources, or settings.
|
||||
|
||||
#### Scenario: User exists with Viewer role
|
||||
- GIVEN the admin has created the user `it@vinogorod.ru` in the Grafana UI
|
||||
- WHEN the user logs in with the shared password
|
||||
- THEN authentication succeeds (Basic auth `/api/user` → HTTP 200)
|
||||
- AND the organization role is `Viewer` (`/api/orgs/1/users` → role "Viewer")
|
||||
|
||||
#### Scenario: Unknown credentials rejected
|
||||
- GIVEN the read-only user `it@vinogorod.ru`
|
||||
- WHEN a request is made with a wrong password
|
||||
- THEN the API returns HTTP 401
|
||||
|
||||
#### Scenario: Read-only enforced
|
||||
- GIVEN the user `it@vinogorod.ru` is logged in as `Viewer`
|
||||
- WHEN the user attempts a privileged operation (e.g. `POST /api/users`,
|
||||
modify datasources)
|
||||
- THEN the request is rejected (HTTP 403/404)
|
||||
|
||||
### Requirement: No admin rights for IT user
|
||||
|
||||
The IT read-only account MUST NOT have admin or editor rights; only viewing
|
||||
of dashboards and logs is permitted.
|
||||
|
||||
#### Scenario: Role is not elevated
|
||||
- GIVEN the user `it@vinogorod.ru`
|
||||
- WHEN checking its org role and admin flag (`/api/user` + `/api/orgs/1/users`)
|
||||
- THEN role is `Viewer` and `isGrafanaAdmin` is false
|
||||
Reference in New Issue
Block a user