Ability for LS to set security user for ES DLS
Open
security
x-pack
- Dominant language
- Java
- Stars
- 14.9k
- Forks
- 3.5k
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 88
Description
*Original comment by @acchen97:*
This is a new processor functionality in the Ingest Node that should be considered for inclusion in Logstash. This allows the setting of the authenticated user info for documents at write time to better enable document level security at query time. For Logstash, I can potentially see this as another config option(s) in the Elasticsearch output instead of a separate filter. We'd also need a way to fetch the user details/metadata.
References:
- https://github.com/elastic/logstash/issues/6007
- https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html#set-security-user-processor
- LINK REDACTED
Contributor guide
Assessment
This issue has not been assessed yet.