Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

non-super user can't create cross cluster index pattern

Open
#698 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
elasticsearch
Domain
api, backend, security

Research direction

Start by reproducing the non-super-user request to /api/index_patterns/_fields_for_wildcard with a pattern such as data: and compare it with the successful super-user behavior. Trace the permissions involved in the index-pattern field lookup; done means an authorized cross-cluster user can create patterns containing : without a 500 response.

Written by the indexing model from the issue text.

Description

Original comment by @LeeDr:

Kibana version: 5.5.0

Elasticsearch version: 5.5.0

Server OS version: Ubuntu

Browser version: Chrome

Browser OS version: Ubuntu

Original install method (e.g. download page, yum, from source, etc.): tar.gz

Description of the problem including expected versus actual behavior:
I think I'm giving a user roles with permissions that should allow them to create a cross cluster index pattern, but it fails.

Steps to reproduce:

  1. set up 2 es nodes so that one is a "local" admin cluster that Kibana uses (9200), and the other is a remote "data" cluster (9210).
  2. Add makelogs data to both clusters
  3. create a makelogs_reader role, that has index patterns makelogs-*, local:makelogs-*, data:makelogs-*, *:makelogs-* and privs read, view_index_metadata, read_cross_cluster
  4. create a kibana_css role that is just like the kibana_user role except add the read_cross_cluster priv on the .kibana* index. (I didn't think this step should be necessary since .kibana isn't cross cluster, but I tried it when things didn't work with kibana_user role)
  5. Create a makelogs_reader user with makelogs_reader and kibana_css roles
  6. log in as that user and try to create any index pattern containing :.
    It fails right after you type the : like data:

Up to the point where I type data I can see Kibana checking if that index exists and getting a 404 as expected. But as soon as I type the : I get the red toast error banner and the console shows this;

Errors in browser console (if relevant):

getFieldsForWildcard(data:)
VM10731:1 GET https://localhost:5601/api/index_patterns/_fields_for_wildcard?pattern=data…5B%22_source%22%2C%22_id%22%2C%22_type%22%2C%22_index%22%2C%22_score%22%5D 500 (Internal Server Error)
(anonymous) @ VM10731:1
(anonymous) @ commons.bundle.js?v=15347:37
sendReq @ commons.bundle.js?v=15347:37
serverRequest @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
(anonymous) @ commons.bundle.js?v=15347:39
completeOutstandingRequest @ commons.bundle.js?v=15347:36
(anonymous) @ commons.bundle.js?v=15347:36
commons.bundle.js?v=15347:38 Error: An internal server error occurred
    at kibana.bundle.js?v=15347:228
    at processQueue (commons.bundle.js?v=15347:38)
    at commons.bundle.js?v=15347:38
    at Scope.$eval (commons.bundle.js?v=15347:39)
    at Scope.$digest (commons.bundle.js?v=15347:39)
    at Scope.$apply (commons.bundle.js?v=15347:39)
    at done (commons.bundle.js?v=15347:37)
    at completeRequest (commons.bundle.js?v=15347:37)
    at XMLHttpRequest.xhr.onload (commons.bundle.js?v=15347:37)
(anonymous) @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
done @ commons.bundle.js?v=15347:37
completeRequest @ commons.bundle.js?v=15347:37
xhr.onload @ commons.bundle.js?v=15347:37

I know the cross cluster config is OK and data:makelogs-* works fine for the elastic super user.

Provide logs and/or server output (if relevant):

The 2 roles I created:

  "makelogs_reader": {
    "cluster": [],
    "indices": [
      {
        "names": [
          "makelogs-*",
          "data:makelogs-*",
          "*:makelogs-*",
          "local:makelogs-*"
        ],
        "privileges": [
          "read",
          "view_index_metadata",
          "read_cross_cluster"
        ],
        "field_security": {
          "grant": [
            "*"
          ]
        }
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  },
  "kibana_ccs": {
    "cluster": [],
    "indices": [
      {
        "names": [
          ".kibana*"
        ],
        "privileges": [
          "manage",
          "create",
          "index",
          "delete",
          "read_cross_cluster"
        ],
        "field_security": {
          "grant": [
            "*"
          ]
        }
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  }
Dominant language
Java
Stars
105
Forks
249
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from elastic/stack-docs

All issues in elastic/stack-docs

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.