grafana/pkg/api
Yuri Tseretyan 1f707d16ed
Apply security patch 357-202503311017.patch (#104490)
* Sanitize paths before evaluating access to route

* use util.CleanRelativePath

---------

Co-authored-by: Andres Martinez Gotor <andres.martinez@grafana.com>
2025-04-24 20:15:17 +01:00
..
apierrors K8s: Fix error conversion for provisioned dashboards (#103074) 2025-03-31 14:34:54 +01:00
avatar Chore: Remove public vars in setting package (#81018) 2024-01-23 12:36:22 +01:00
datasource Prometheus: Add support for cloud partners Prometheus data sources (#103482) 2025-04-10 12:49:11 -07:00
dtos K8s/Dashboard: Promote from alpha1 to beta1 (#104009) 2025-04-23 20:54:35 +03:00
frontendlogging Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
pluginproxy Apply security patch 357-202503311017.patch (#104490) 2025-04-24 20:15:17 +01:00
response Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
routing Grafana: Replace magic number with a constant variable in response status (#80132) 2024-02-27 18:39:51 +02:00
static API: Extract OpenAPI specification from source code using go-swagger (#40528) 2022-02-08 13:38:43 +01:00
webassets Frontend: Extract CSS imports into files (#94655) 2024-10-16 11:10:34 +02:00
accesscontrol.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin_encryption.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
admin_provisioning.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_provisioning_test.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
admin_test.go Auth: Add anonymous users view and stats (#78685) 2023-11-29 17:58:41 +01:00
admin_users.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
admin_users_test.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
alerting.go Alerting: Remove legacy alerting (#83671) 2024-03-14 15:36:35 +01:00
annotations.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
annotations_test.go Annotations: Fix annotations scope resolver (#102612) 2025-03-24 16:00:07 +01:00
api.go Dashboard Restore: Remove experimental functionality under feature flag dashboardRestore for now - this will be reworked (#103204) 2025-04-03 02:52:54 -05:00
api_test.go Chore: Update test database initialization (#81673) 2024-02-09 09:35:39 -05:00
apikey.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
basic_auth.go
basic_auth_test.go
common_test.go K8s: refactor build handler chain func to allow easier injection from enterprise (#100777) 2025-02-15 04:08:00 +02:00
dashboard.go Access control: Make sure that user permission cache is cleared after new dashboard and folder creation (#104193) 2025-04-24 16:02:39 +03:00
dashboard_permission.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
dashboard_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
dashboard_snapshot.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
dashboard_snapshot_test.go RBAC: Remove dashboard guardians pt 3 (#102558) 2025-03-21 10:44:16 +00:00
dashboard_test.go Access control: Make sure that user permission cache is cleared after new dashboard and folder creation (#104193) 2025-04-24 16:02:39 +03:00
dataproxy.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
datasources.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
datasources_test.go LBAC for datasources: GA (#99511) 2025-02-20 10:26:46 +00:00
ds_query.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
ds_query_test.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
fakes.go Preinstall: Allow to set a download URL (#96535) 2024-11-29 16:02:33 +01:00
folder.go Access control: Make sure that user permission cache is cleared after new dashboard and folder creation (#104193) 2025-04-24 16:02:39 +03:00
folder_bench_test.go Access control: Make sure that user permission cache is cleared after new dashboard and folder creation (#104193) 2025-04-24 16:02:39 +03:00
folder_permission.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
folder_permission_test.go AccessControl: Use UIDs for Resource permissions frontend (#95552) 2024-10-31 16:17:13 +01:00
folder_test.go K8s/Folders: Use v1beta1 and app-sdk based spec (#103975) 2025-04-14 23:20:10 +03:00
frontend_logging.go Chore: Bump Go to 1.23.0 (#92105) 2024-08-21 11:40:42 -04:00
frontend_logging_test.go Chore: use any rather than interface{} (#74066) 2023-08-30 18:46:47 +03:00
frontend_metrics.go Chore: Move ReqContext to contexthandler service (#62102) 2023-01-27 08:50:36 +01:00
frontendsettings.go Dashboards: Add a config setting that limits the number of series that will be displayed in a panel. Users can opt in to render all series. (#103405) 2025-04-11 13:56:58 +02:00
frontendsettings_test.go i18n: wires up translations for plugins (#102853) 2025-03-31 06:38:38 +02:00
grafana_com_proxy.go Plugins: Use grafana-com sso_api_token (#97096) 2024-12-02 16:04:05 +01:00
health.go Spanner-related fixes (#102376) 2025-03-19 12:34:44 +01:00
health_test.go Auth: Separate anonymous settings to its own struct (#97791) 2024-12-13 10:46:27 +01:00
http_server.go Plugins: Remove support for secrets manager plugins (#101467) 2025-03-20 10:00:59 +00:00
http_server_test.go Grafana: Adds support for PKCS1 encrypted certs (#93451) 2024-09-19 15:03:06 -03:00
index.go i18n: Update internationalization/dates.ts to use locale (#103731) 2025-04-11 11:24:40 +02:00
login.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
login_oauth.go Auth: Fix redirection when auto_login is enabled (#94311) 2024-10-07 14:59:00 +02:00
login_oauth_test.go Auth: Remove auth broker flag and clean up login handlers (#73109) 2023-08-10 09:56:04 +02:00
login_test.go Authlib: Use types package rather than claims (#99243) 2025-01-21 12:06:55 +03:00
org.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_invite.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_invite_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
org_test.go Authlib: Use types package rather than claims (#99243) 2025-01-21 12:06:55 +03:00
org_users.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
org_users_test.go IDToken: cache invalidation (#100592) 2025-02-13 14:10:58 +01:00
password.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00
playlist.go Playlists: Remove kubernetesPlaylists flag (#104171) 2025-04-22 10:39:40 +02:00
plugin_checks.go Plugins: Avoid returning 404 for AutoEnabled apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_checks_test.go Plugins: Avoid returning 404 for AutoEnabled apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_dashboards.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_dashboards_test.go Chore: Evaluate if an app is disabled for API requests (#79564) 2023-12-15 16:37:39 +01:00
plugin_metrics.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_metrics_test.go Chore: Refactor backend plugin errors (#74928) 2023-09-25 11:56:03 +02:00
plugin_proxy.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_proxy_test.go Plugins: Preserve trailing slash in plugin proxy (#86859) 2024-06-05 13:36:14 +02:00
plugin_resource.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugin_resource_test.go Jaeger: run health check through backend (#99322) 2025-01-24 19:37:36 +07:00
plugins.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
plugins_test.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
preferences.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
preferences_test.go Identity: Unfurl UserID and Email in pkg/api to user identity.Requester (#76112) 2023-10-09 16:07:28 +02:00
quota.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
quota_test.go Add auth spans and remove deduplication code for scopes (#89804) 2024-07-02 22:08:57 -08:00
README.md Swagger: Fix sync issue with enterprise (#97696) 2024-12-09 21:21:22 +02:00
render.go Rendering: Add support for rate limiter (#103987) 2025-04-24 15:31:19 +02:00
search.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
short_url.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
short_url_test.go Chore: Fix goimports grouping in pkg/api (#62419) 2023-01-30 08:18:26 +00:00
signup.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
swagger.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
swagger_responses.go K8s: Schema v2: Return 406 in /api (#101842) 2025-03-07 18:20:02 -06:00
swagger_tags.json Browse Dashboards: Update docs to remove reference to General folder (#74528) 2023-09-08 03:57:16 +01:00
user.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
user_test.go Return correct disabled status when looking up a user (#103182) 2025-04-02 13:38:10 +02:00
user_token.go CI: Bump golangci-lint to 2.0.2 (#103572) 2025-04-10 14:42:23 +02:00
user_token_test.go AuthToken: Remove client token rotation feature toggle (#82886) 2024-02-16 15:03:37 +01:00
utils.go Auth: Fix SAML user IsExternallySynced not being set correctly (#98487) 2025-01-10 17:37:37 +01:00

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).

For enterprise endpoints make sure you add the enterprise tag as well.


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2