non-super user can't create cross cluster index pattern

Đang mở
#698 6 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
elasticsearch
Lĩnh vực
api, backend, security

Hướng nghiên cứu

Bắt đầu bằng cách tái hiện request của người dùng không phải super-user tới /api/index_patterns/_fields_for_wildcard với một pattern như data: và so sánh với hành vi thành công của super-user. Theo dõi các quyền liên quan đến việc tra cứu field của index-pattern; công việc được xem là hoàn tất khi một người dùng cross-cluster đã được cấp quyền có thể tạo các pattern chứa : mà không nhận được response 500.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Original comment by @LeeDr:

Kibana version: 5.5.0

Elasticsearch version: 5.5.0

Server OS version: Ubuntu

Browser version: Chrome

Browser OS version: Ubuntu

Original install method (e.g. download page, yum, from source, etc.): tar.gz

Description of the problem including expected versus actual behavior:
I think I'm giving a user roles with permissions that should allow them to create a cross cluster index pattern, but it fails.

Steps to reproduce:

  1. set up 2 es nodes so that one is a "local" admin cluster that Kibana uses (9200), and the other is a remote "data" cluster (9210).
  2. Add makelogs data to both clusters
  3. create a makelogs_reader role, that has index patterns makelogs-*, local:makelogs-*, data:makelogs-*, *:makelogs-* and privs read, view_index_metadata, read_cross_cluster
  4. create a kibana_css role that is just like the kibana_user role except add the read_cross_cluster priv on the .kibana* index. (I didn't think this step should be necessary since .kibana isn't cross cluster, but I tried it when things didn't work with kibana_user role)
  5. Create a makelogs_reader user with makelogs_reader and kibana_css roles
  6. log in as that user and try to create any index pattern containing :.
    It fails right after you type the : like data:

Up to the point where I type data I can see Kibana checking if that index exists and getting a 404 as expected. But as soon as I type the : I get the red toast error banner and the console shows this;

Errors in browser console (if relevant):

getFieldsForWildcard(data:)
VM10731:1 GET https://localhost:5601/api/index_patterns/_fields_for_wildcard?pattern=data…5B%22_source%22%2C%22_id%22%2C%22_type%22%2C%22_index%22%2C%22_score%22%5D 500 (Internal Server Error)
(anonymous) @ VM10731:1
(anonymous) @ commons.bundle.js?v=15347:37
sendReq @ commons.bundle.js?v=15347:37
serverRequest @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
(anonymous) @ commons.bundle.js?v=15347:39
completeOutstandingRequest @ commons.bundle.js?v=15347:36
(anonymous) @ commons.bundle.js?v=15347:36
commons.bundle.js?v=15347:38 Error: An internal server error occurred
    at kibana.bundle.js?v=15347:228
    at processQueue (commons.bundle.js?v=15347:38)
    at commons.bundle.js?v=15347:38
    at Scope.$eval (commons.bundle.js?v=15347:39)
    at Scope.$digest (commons.bundle.js?v=15347:39)
    at Scope.$apply (commons.bundle.js?v=15347:39)
    at done (commons.bundle.js?v=15347:37)
    at completeRequest (commons.bundle.js?v=15347:37)
    at XMLHttpRequest.xhr.onload (commons.bundle.js?v=15347:37)
(anonymous) @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
done @ commons.bundle.js?v=15347:37
completeRequest @ commons.bundle.js?v=15347:37
xhr.onload @ commons.bundle.js?v=15347:37

I know the cross cluster config is OK and data:makelogs-* works fine for the elastic super user.

Provide logs and/or server output (if relevant):

The 2 roles I created:

  "makelogs_reader": {
    "cluster": [],
    "indices": [
      {
        "names": [
          "makelogs-*",
          "data:makelogs-*",
          "*:makelogs-*",
          "local:makelogs-*"
        ],
        "privileges": [
          "read",
          "view_index_metadata",
          "read_cross_cluster"
        ],
        "field_security": {
          "grant": [
            "*"
          ]
        }
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  },
  "kibana_ccs": {
    "cluster": [],
    "indices": [
      {
        "names": [
          ".kibana*"
        ],
        "privileges": [
          "manage",
          "create",
          "index",
          "delete",
          "read_cross_cluster"
        ],
        "field_security": {
          "grant": [
            "*"
          ]
        }
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  }
Ngôn ngữ chính
Java
Star
105
Fork
249
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của elastic/stack-docs

Tất cả issue của elastic/stack-docs

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.