Support access:
security policies on Explore
and Canvas
resources
#5728
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds support for
access:
security policies on canvas and explore resources. Among other use cases, this enables hiding dashboards that will anyway fail to render for people who don't have access to the underlying metrics views.A policy on an explore/canvas resource does not prevent direct queries to the underlying metrics views, so it is still recommended to define security policies directly on metrics views.
Changes:
access:
security rules on resources oftype: explore
andtype: canvas
.explore
resources.Examples:
Closes #5500.