Unified storage: refuse a check the service token cannot delegate (#132990)
* Unified storage: warn when the service token cannot delegate a check authlib denies a check on its own when the calling service has no delegated permission for the group and resource, without asking the authz service. That denial is indistinguishable from the user lacking access, so a missing permission surfaced only as empty results. authzLimitedClient now logs a warning and counts the case in grafana_grpc_authz_limited_client_missing_delegated_permission_total, per group, resource and verb. * Unified storage: refuse a check the service token cannot delegate Warning about it still left the request returning nothing. Refuse instead, so a missing delegated permission fails the request rather than reading as a user without access. Identities carrying no token permissions at all are left alone: single-tenant and in-process callers look like that, and the underlying client decides there.
P
Peter Štibraný committed
1f4585b76dc06caff2a205d9f665fd211d72bc09
Parent: 46e98fa
Committed by GitHub <noreply@github.com>
on 9/18/2026, 1:18:02 PM