Skip to content

Command cat/indices will filter results per the Do Not Fail On Forbidden setting#3236

Merged
RyanL1997 merged 9 commits intoopensearch-project:mainfrom
derek-ho:cat_indices
Aug 29, 2023
Merged

Command cat/indices will filter results per the Do Not Fail On Forbidden setting#3236
RyanL1997 merged 9 commits intoopensearch-project:mainfrom
derek-ho:cat_indices

Conversation

@derek-ho
Copy link
Copy Markdown
Collaborator

@derek-ho derek-ho commented Aug 24, 2023

Description

This change allows for DNFOF behavior on the _cat/_indices API. It adds the required index permissions into the DNFOF regex to be picked up in the DNFOF code path. Previously it was being skipped/returning 403, since the index permissions were not in the regex.

Issues Resolved

Fix: #1815

Is this a backport? If so, please add backport PR # and/or commits #

Testing

[Please provide details of testing done: unit testing, integration testing and manual testing]

Check List

  • New functionality includes testing
  • New functionality has been documented
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Derek Ho <dxho@amazon.com>
Signed-off-by: Derek Ho <dxho@amazon.com>
Signed-off-by: Derek Ho <dxho@amazon.com>
Signed-off-by: Derek Ho <dxho@amazon.com>
@derek-ho derek-ho changed the title Cat indices Enable DNFOF on cat indices API Aug 24, 2023
@derek-ho derek-ho marked this pull request as ready for review August 24, 2023 16:11
Signed-off-by: Derek Ho <dxho@amazon.com>
@codecov
Copy link
Copy Markdown

codecov bot commented Aug 24, 2023

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 62.49%. Comparing base (46dfd84) to head (c12333c).
⚠️ Report is 896 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##               main    #3236    +/-   ##
==========================================
  Coverage     62.49%   62.49%            
- Complexity     3351     3400    +49     
==========================================
  Files           254      259     +5     
  Lines         19732    20056   +324     
  Branches       3334     3370    +36     
==========================================
+ Hits          12331    12534   +203     
- Misses         5773     5872    +99     
- Partials       1628     1650    +22     
Files with missing lines Coverage Δ
...earch/security/privileges/PrivilegesEvaluator.java 73.20% <100.00%> (+0.08%) ⬆️

... and 19 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: Derek Ho <dxho@amazon.com>
Signed-off-by: Derek Ho <dxho@amazon.com>
@peternied peternied changed the title Enable DNFOF on cat indices API Command cat/indices will filter results per the Do Not Fail On Forbidden setting Aug 28, 2023
@RyanL1997 RyanL1997 merged commit 4c095d2 into opensearch-project:main Aug 29, 2023
@opensearch-trigger-bot
Copy link
Copy Markdown
Contributor

The backport to 2.x failed:

The process '/usr/bin/git' failed with exit code 128

To backport manually, run these commands in your terminal:

# Navigate to the root of your repository
cd $(git rev-parse --show-toplevel)
# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/security/backport-2.x 2.x
# Navigate to the new working tree
pushd ../.worktrees/security/backport-2.x
# Create a new branch
git switch --create backport/backport-3236-to-2.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 4c095d27fd30ec279dd4214e72a831ea9123a693
# Push it to GitHub
git push --set-upstream origin backport/backport-3236-to-2.x
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/security/backport-2.x

Then, create a pull request where the base branch is 2.x and the compare/head branch is backport/backport-3236-to-2.x.

@peternied
Copy link
Copy Markdown
Member

Backport likely failed due to the integration tests not being backported

derek-ho added a commit to derek-ho/security that referenced this pull request Aug 29, 2023
…idden setting (opensearch-project#3236)

This change allows for DNFOF behavior on the _cat/_indices API. It adds
the required index permissions into the DNFOF regex to be picked up in
the DNFOF code path. Previously it was being skipped/returning 403,
since the index permissions were not in the regex.

Fix: opensearch-project#1815

Is this a backport? If so, please add backport PR # and/or commits #

[Please provide details of testing done: unit testing, integration
testing and manual testing]

- [ ] New functionality includes testing
- [ ] New functionality has been documented
- [ ] Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and
signing off your commits, please check
[here](https://github.com/opensearch-project/OpenSearch/blob/main/CONTRIBUTING.md#developer-certificate-of-origin).

---------

Signed-off-by: Derek Ho <dxho@amazon.com>
(cherry picked from commit 4c095d2)
Signed-off-by: Derek Ho <dxho@amazon.com>
cwperks pushed a commit that referenced this pull request Aug 29, 2023
…ot fail on forbidden setting (#3258)

### Description
Backport 4c095d2 of #3236 

### Check List
- [ ] New functionality includes testing
- [ ] New functionality has been documented
- [X] Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and
signing off your commits, please check
[here](https://github.com/opensearch-project/OpenSearch/blob/main/CONTRIBUTING.md#developer-certificate-of-origin).

---------

Signed-off-by: Derek Ho <dxho@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] do_not_fail_on_forbidden_empty does not work for cat api

5 participants