Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecate or warn for system indices in user-defined roles #76713

Open
williamrandolph opened this issue Aug 19, 2021 · 2 comments
Open

Deprecate or warn for system indices in user-defined roles #76713

williamrandolph opened this issue Aug 19, 2021 · 2 comments
Labels
:Core/Infra/Core Core issues without another label >enhancement :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Core/Infra Meta label for core/infra team Team:Security Meta label for security team

Comments

@williamrandolph
Copy link
Contributor

This is a follow-up from a suggestion that @albertzaharovits made in #74212.

If a user currently has an index permission in a user-defined role that specifies only system indices, do we need to issue a deprecation warning? Or should we

We need to find out what the application behavior would be in this situation and determine whether or not we can successfully identify this situation. We don't want to issue warnings in cases where the index permission patterns can cover system indices as well as other indices; consider the trivial case of "*" for all indices, which should be allowed. But if a user has created an alternate permission for .security-* or .kibana, what will happen? Do we need to warn about this case or just let it fail silently?

It's possible that we already do some kind of checking or handling here, in which case we can close this issue.

@williamrandolph williamrandolph added >enhancement :Core/Infra/Core Core issues without another label :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC labels Aug 19, 2021
@elasticmachine elasticmachine added Team:Core/Infra Meta label for core/infra team Team:Security Meta label for security team labels Aug 19, 2021
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-core-infra (Team:Core/Infra)

@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Core/Infra/Core Core issues without another label >enhancement :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Core/Infra Meta label for core/infra team Team:Security Meta label for security team
Projects
None yet
Development

No branches or pull requests

2 participants