# grafana-access-control Specification ## Purpose TBD - created by archiving change grafana-readonly-user. Update Purpose after archive. ## Requirements ### Requirement: Read-only Grafana user for Vinogorod IT Grafana MUST provide a read-only account for the Vinogorod IT department: login `it@vinogorod.ru`, role `Viewer`, in the default organization (orgId 1). The account MUST NOT be able to create, edit, or delete dashboards, datasources, or settings. #### Scenario: User exists with Viewer role - GIVEN the admin has created the user `it@vinogorod.ru` in the Grafana UI - WHEN the user logs in with the shared password - THEN authentication succeeds (Basic auth `/api/user` → HTTP 200) - AND the organization role is `Viewer` (`/api/orgs/1/users` → role "Viewer") #### Scenario: Unknown credentials rejected - GIVEN the read-only user `it@vinogorod.ru` - WHEN a request is made with a wrong password - THEN the API returns HTTP 401 #### Scenario: Read-only enforced - GIVEN the user `it@vinogorod.ru` is logged in as `Viewer` - WHEN the user attempts a privileged operation (e.g. `POST /api/users`, modify datasources) - THEN the request is rejected (HTTP 403/404) ### Requirement: No admin rights for IT user The IT read-only account MUST NOT have admin or editor rights; only viewing of dashboards and logs is permitted. #### Scenario: Role is not elevated - GIVEN the user `it@vinogorod.ru` - WHEN checking its org role and admin flag (`/api/user` + `/api/orgs/1/users`) - THEN role is `Viewer` and `isGrafanaAdmin` is false