elastic / elastic/stack-docs

Clarify File-based grants are not visible with API calls

Aperta
#211 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
:Security
Lingua principale
Java
Stelle
105
Fork
249
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

The following is true of all versions: The APIs (user, role, role mapping) only work with objects that were defined via the API.

Objects (users, roles, mappings) defined in files need to be managed via the files (or the `users` CLI tool which uses the files).

API exploration calls (and consecutively, Kibana) will not report roles and mappings defined in files.

Example, where role production_user is defined in roles.yml and user "test" is a file realm user created with the users CLI tool.

```
curl -X GET -u test:password http://localhost:9200/_xpack/security/_authenticate
{"username":"test","roles":["production_user"],"full_name":null,"email":null,"metadata":{},"enabled":true}[root@localhost x-pack]#

curl -X GET -u test:password http://localhost:9200/_xpack/security/role/production_user
{}

curl -X GET -u elastic:password http://localhost:9200/_xpack/security/user/test
{}
```

Some places to update docs to reflect this behavior:

https://www.elastic.co/guide/en/elastic-stack-overview/6.6/defining-roles.html#roles-management-file

https://www.elastic.co/guide/en/elastic-stack-overview/6.6/mapping-roles.html#mapping-roles-file

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.