-
Notifications
You must be signed in to change notification settings - Fork 25.8k
Switch security to authorise on indices rather than aliases #29874
Copy link
Copy link
Open
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC>breaking>featureTeam:SecurityMeta label for security teamMeta label for security team
Description
Original comment by @tvernum:
We've discussed this a number of times in the past. The current approach of authorising based on aliases was an attempt to offer something a bit like DLS, prior to our proper DLS implementation.
Switching to only authorise on indices would make a lot of the code simpler, but would be a breaking change (and is complicated by license levels, aliases work in Gold, but DLS is in Platinum).
Opening this ticket as a place for discussion.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC>breaking>featureTeam:SecurityMeta label for security teamMeta label for security team
Type
Fields
Give feedbackNo fields configured for issues without a type.