From 54b09d9878cb421ed845f0a724622a14bc551994 Mon Sep 17 00:00:00 2001 From: brettkolodny Date: Thu, 20 Feb 2025 09:56:57 -0500 Subject: [PATCH] fix: show an error banner if the user does not have permission to view the audit page (#16637) --- coderd/coderd.go | 19 +++++++++++++++++++ site/src/pages/AuditPage/AuditPage.tsx | 9 +++++++++ 2 files changed, 28 insertions(+) diff --git a/coderd/coderd.go b/coderd/coderd.go index 93aeb02adb..65b943cd3a 100644 --- a/coderd/coderd.go +++ b/coderd/coderd.go @@ -930,6 +930,25 @@ func New(options *Options) *API { r.Route("/audit", func(r chi.Router) { r.Use( apiKeyMiddleware, + // This middleware only checks the site and orgs for the audit_log read + // permission. + // In the future if it makes sense to have this permission on the user as + // well we will need to update this middleware to include that check. + func(next http.Handler) http.Handler { + return http.HandlerFunc(func(rw http.ResponseWriter, r *http.Request) { + if api.Authorize(r, policy.ActionRead, rbac.ResourceAuditLog) { + next.ServeHTTP(rw, r) + return + } + + if api.Authorize(r, policy.ActionRead, rbac.ResourceAuditLog.AnyOrganization()) { + next.ServeHTTP(rw, r) + return + } + + httpapi.Forbidden(rw) + }) + }, ) r.Get("/", api.auditLogs) diff --git a/site/src/pages/AuditPage/AuditPage.tsx b/site/src/pages/AuditPage/AuditPage.tsx index 68f566b4bf..efcf2068f1 100644 --- a/site/src/pages/AuditPage/AuditPage.tsx +++ b/site/src/pages/AuditPage/AuditPage.tsx @@ -1,4 +1,5 @@ import { paginatedAudits } from "api/queries/audits"; +import { ErrorAlert } from "components/Alert/ErrorAlert"; import { useFilter } from "components/Filter/Filter"; import { useUserFilterMenu } from "components/Filter/UserFilter"; import { isNonInitialPage } from "components/PaginationWidget/utils"; @@ -67,6 +68,14 @@ const AuditPage: FC = () => { }), }); + if (auditsQuery.error) { + return ( +
+ +
+ ); + } + return ( <>