[pull] main from SigNoz:main - #851
Merged
Merged
Conversation
…races (#12203) Temporal Cloud Metrics scrapes an OpenMetrics endpoint but only showed under APM/Traces, bundled with the Go and TypeScript SDKs. Split it into a standalone metrics card and trimmed the Temporal APM card to Go and TypeScript. Closes SigNoz/growth-pod#1122
* feat(authz): provision telemetry roles with plaintext selectors and hashed tuples Accept a user-facing telemetry selector string (<query_type>/<key>/<value> with trailing wildcards), validate and canonicalize it, store it as-is in the role JSON record, and hash it only at the OpenFGA boundary in Object(). Grant and check both flow through Object() so the hashes match; the plaintext record stays the readable source of truth for display and recreation. Because the hash is one-way, role Update diffs at the tuple level via DiffTuples instead of reconstructing transaction groups from stored tuples. * refactor(authz): rename telemetry selector helpers and unexport hash Rename grant_selector.go to selector.go, CanonicalizeTelemetryGrantSelector to NewTelemetryGrantSelector, and CanonicalTelemetryGrantKey to NewTelemetryGrantKey. Unexport telemetrySelectorHash since Object() is its only caller. * fix(authz): expand telemetry ladder in the permission check API The check API only probed the exact selector plus the full wildcard, so a scoped grant like builder_query/service.name/* reported a concrete query as unauthorized even though enforcement allowed it. Relocate the grant selector ladder to telemetrytypes as NewTelemetryGrantSelectors so both enforcement and the check API share it, and canonicalize plus fan out the ladder for telemetry check transactions. Non-telemetry resources keep the exact-plus-wildcard probe. * refactor(authz): move newCheckSelectors to the bottom of tuple.go * fix(authz): reject key-scoped selectors for promql and clickhouse_sql Only builder_query and builder_sub_query extract key-scoped selectors on the check side, so a grant like clickhouse_sql/service.name/signoz could never match anything. Track key-scope support per query type and reject the <query_type>/<key>/<value> form for query types that only emit <query_type>/*. * test(authz): use a valid promql selector in the check API test The promql/service.name/service-a case became invalid input after key-scoped promql/clickhouse_sql selectors were rejected, so the check endpoint returned 400 instead of 200. Use promql/* to keep exercising the different-query-type denial with a valid selector. * feat(authz): allow signoz.workspace.key.id as a telemetry grant key Add signoz.workspace.key.id to the telemetry grant key allowlist so roles can scope telemetry access by ingestion key, alongside service.name. Grant validation and check-side extraction both pick it up through the shared NewTelemetryGrantKey path; bare and resource.-prefixed spellings fold to the same canonical key. * Revert "feat(authz): allow signoz.workspace.key.id as a telemetry grant key" This reverts commit c50d122. * feat(authz): scope telemetry grants by signoz.workspace.key.id Make signoz.workspace.key.id the sole telemetry grant key instead of service.name, so roles scope telemetry access by ingestion key. The allowlist is the only production change; grant validation and check-side extraction are name-agnostic. Update the querierauthz integration suite and unit tests to the new key. * test(authz): update query_range_resources extractor tests to signoz.workspace.key.id The grant-key switch left this extractor test filtering on and expecting builder_query/service.name/... IDs, which now fall back to builder_query/*. Rename the filters and expectations to signoz.workspace.key.id.
…own clipping & time-window fixes (#12146) * fix(dashboards-v2): carry active time window across panel editor navigation Opening, creating, or leaving the V2 panel editor now preserves the selected time range (relative or custom) via URL params derived from Redux global time, so a custom range picked in the editor isn't reset to the dashboard default on return. Adds timeParamsFromGlobalTime + useTimeSearchParams; useOpenPanelEditor now takes an options object ({ handoffState, search }) and appends the time params, and useCreatePanel routes through it. * fix(dashboards-v2): sync panel editor preview to the staged query on browser back/forward The query builder reverts both currentQuery and stagedQuery via initQueryBuilderData on a URL re-stage (chiefly browser Back/Forward), but the preview kept the last Run's result. Commit the staged query into the draft whenever it re-stages outside an explicit Run, so the preview follows. Live edits touch only currentQuery, so they still wait for Run; commitQuery no-ops when unchanged. * fix(dashboards-v2): stop query-builder dropdowns being clipped in the panel editor The panel editor renders the query builder inside an overflow:hidden resizable pane, so antd Select popups (group-by, order-by, having, metric name, aggregator, units) were cut off. Make the shared QB filters defer to an ancestor ConfigProvider's popup container (falling back to trigger.parentNode) via useSelectPopupContainer, and wrap the editor's builder in a ConfigProvider that portals popups to document.body. Scoped to the editor host, so the View modal keeps its own container and other surfaces are unchanged. * fix(dashboards-v2): anchor panel editor dirty check to saved panel; retain query edits on refresh The editor re-derived its dirty baseline from the incoming panel prop, which is seeded from transient state — a stale URL compositeQuery after a refresh or the View-mode handoff spec — instead of the persisted panel. So the draft was compared against an already-edited baseline: after a refresh the panel showed the saved query yet read dirty (inverted), and a View->Edit query change read clean with Save disabled. - Thread a savedPanel baseline (existingPanel) through PanelEditorPage -> PanelEditorContainer -> usePanelEditSession, distinct from the seed panel. - usePanelEditorDraft compares isSpecDirty against savedPanel; the draft still seeds from the (possibly handed-off) panel. - usePanelEditorQuerySync computes isQueryDirty as a V5-envelope comparison of the live query against the saved queries, routing both sides through the same fromPerses->toPerses round-trip so builder-added defaults absent from an older stored query never read an untouched panel as modified. Replaces the racy captured-first-stagedQuery baseline. - Drop the mount forceReset on useShareBuilderUrl (both its reasons are now moot) so a refresh / browser Back-Forward hydrates the edited query from the URL and the staged-query effect syncs it into the draft — query edits survive a refresh instead of reverting to the saved query. Add real-QueryBuilderProvider integration tests covering untouched-not-dirty (incl. an older/minimal stored query), refresh retention, and handoff-dirty; update the draft + query-sync unit tests.
…selection (#12198) * feat(share): support a page-specific extra option in the share dialog * feat(dashboard-v2): share a dashboard link with the current variable selection
…origins (#12172) * fix(session): use global external_url instead of ref param for SSO state The sessions/context endpoint no longer reads the client-controlled ref query param to build the SSO state and callback URLs. Each callback authn provider now derives the site URL from the server-configured global external_url, and siteURL is removed from the CallbackAuthN and session Module interfaces. * fix(session): validate ref and callback state against global allowed_origins Instead of deriving SSO urls from the global external_url, keep the ref roundtrip and validate its origin against the new optional global.allowed_origins config. The callback state url is re-validated before tokens are attached to it, closing the forged RelayState/state exfiltration path. When allowed_origins is not configured, redirect targets are not validated, preserving existing installs. * fix(session): scope ref origin validation to sso auth domains Move the allowed_origins check from the sessions/context handler to getOrgSessionContext, right before the SSO login URL is built. A disallowed ref no longer fails the whole request; only orgs with an SSO-enabled auth domain get a per-org warning with password fallback.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )