Skip to content

Allow built-in monitoring_user role to call GET _xpack API#38210

Merged
ycombinator merged 1 commit intoelastic:6.xfrom
ycombinator:backport-38060
Feb 1, 2019
Merged

Allow built-in monitoring_user role to call GET _xpack API#38210
ycombinator merged 1 commit intoelastic:6.xfrom
ycombinator:backport-38060

Conversation

@ycombinator
Copy link
Copy Markdown
Contributor

Backport of #38060 to 6.x. Original description:

This PR adds the monitor/xpack/info cluster-level privilege to the built-in monitoring_user role.

This privilege is required for the Monitoring UI to call the GET _xpack API on the Monitoring Cluster. It needs to do this in order to determine the license of the Monitoring Cluster, which further determines whether Cluster Alerts are shown to the user or not.

Resolves #37970.

…8060)

This PR adds the `monitor/xpack/info` cluster-level privilege to the built-in `monitoring_user` role.

This privilege is required for the Monitoring UI to call the `GET _xpack API` on the Monitoring Cluster. It needs to do this in order to determine the license of the Monitoring Cluster, which further determines whether Cluster Alerts are shown to the user or not.

Resolves elastic#37970.
@ycombinator ycombinator added >bug :Core/Infra/Monitoring DEPRECATED, DO NOT USE :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC backport labels Feb 1, 2019
@ycombinator ycombinator requested a review from tvernum February 1, 2019 17:03
@elasticmachine
Copy link
Copy Markdown
Collaborator

Pinging @elastic/es-core-features

@elasticmachine
Copy link
Copy Markdown
Collaborator

Pinging @elastic/es-security

@ycombinator ycombinator requested a review from jaymode February 1, 2019 19:22
Copy link
Copy Markdown
Member

@jaymode jaymode left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ycombinator ycombinator merged commit 55e0019 into elastic:6.x Feb 1, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport >bug :Core/Infra/Monitoring DEPRECATED, DO NOT USE :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants