elastic / elastic/stack-docs

non-super user can't create cross cluster index pattern

Abierto
#698 6 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Java
Estrellas
105
Forks
249
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

*Original comment by @LeeDr:*

**Kibana version**: 5.5.0

**Elasticsearch version**: 5.5.0

**Server OS version**: Ubuntu

**Browser version**: Chrome

**Browser OS version**: Ubuntu

**Original install method (e.g. download page, yum, from source, etc.)**: tar.gz

**Description of the problem including expected versus actual behavior**:
I think I'm giving a user roles with permissions that should allow them to create a cross cluster index pattern, but it fails.

**Steps to reproduce**:
1. set up 2 es nodes so that one is a "local" admin cluster that Kibana uses (9200), and the other is a remote "data" cluster (9210).
2. Add makelogs data to both clusters
3. create a `makelogs_reader` role, that has index patterns `makelogs-*, local:makelogs-*, data:makelogs-*, *:makelogs-*` and privs `read, view_index_metadata, read_cross_cluster`
4. create a `kibana_css` role that is just like the kibana_user role except add the `read_cross_cluster` priv on the .kibana* index. (I didn't think this step should be necessary since .kibana isn't cross cluster, but I tried it when things didn't work with kibana_user role)
5. Create a `makelogs_reader` user with `makelogs_reader` and `kibana_css` roles
6. log in as that user and try to create any index pattern containing `:`.
It fails right after you type the `:` like `data:`

Up to the point where I type `data` I can see Kibana checking if that index exists and getting a 404 as expected. But as soon as I type the `:` I get the red toast error banner and the console shows this;

**Errors in browser console (if relevant)**:
```
getFieldsForWildcard(data:)
VM10731:1 GET https://localhost:5601/api/index_patterns/_fields_for_wildcard?pattern=data…5B%22_source%22%2C%22_id%22%2C%22_type%22%2C%22_index%22%2C%22_score%22%5D 500 (Internal Server Error)
(anonymous) @ VM10731:1
(anonymous) @ commons.bundle.js?v=15347:37
sendReq @ commons.bundle.js?v=15347:37
serverRequest @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
(anonymous) @ commons.bundle.js?v=15347:39
completeOutstandingRequest @ commons.bundle.js?v=15347:36
(anonymous) @ commons.bundle.js?v=15347:36
commons.bundle.js?v=15347:38 Error: An internal server error occurred
at kibana.bundle.js?v=15347:228
at processQueue (commons.bundle.js?v=15347:38)
at commons.bundle.js?v=15347:38
at Scope.$eval (commons.bundle.js?v=15347:39)
at Scope.$digest (commons.bundle.js?v=15347:39)
at Scope.$apply (commons.bundle.js?v=15347:39)
at done (commons.bundle.js?v=15347:37)
at completeRequest (commons.bundle.js?v=15347:37)
at XMLHttpRequest.xhr.onload (commons.bundle.js?v=15347:37)
(anonymous) @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:37
processQueue @ commons.bundle.js?v=15347:38
(anonymous) @ commons.bundle.js?v=15347:38
$eval @ commons.bundle.js?v=15347:39
$digest @ commons.bundle.js?v=15347:39
$apply @ commons.bundle.js?v=15347:39
done @ commons.bundle.js?v=15347:37
completeRequest @ commons.bundle.js?v=15347:37
xhr.onload @ commons.bundle.js?v=15347:37
```

I know the cross cluster config is OK and `data:makelogs-*` works fine for the `elastic` super user.

**Provide logs and/or server output (if relevant)**:

The 2 roles I created:
```
"makelogs_reader": {
"cluster": [],
"indices": [
{
"names": [
"makelogs-*",
"data:makelogs-*",
"*:makelogs-*",
"local:makelogs-*"
],
"privileges": [
"read",
"view_index_metadata",
"read_cross_cluster"
],
"field_security": {
"grant": [
"*"
]
}
}
],
"run_as": [],
"metadata": {},
"transient_metadata": {
"enabled": true
}
},
"kibana_ccs": {
"cluster": [],
"indices": [
{
"names": [
".kibana*"
],
"privileges": [
"manage",
"create",
"index",
"delete",
"read_cross_cluster"
],
"field_security": {
"grant": [
"*"
]
}
}
],
"run_as": [],
"metadata": {},
"transient_metadata": {
"enabled": true
}
}
```

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Línea de trabajo

Comienza reproduciendo la solicitud de un usuario que no sea superusuario a `/api/index_patterns/_fields_for_wildcard` con un patrón como `data:` y compárala con el comportamiento exitoso del superusuario. Rastrea los permisos implicados en la búsqueda de campos del patrón de índice; el trabajo estará terminado cuando un usuario autorizado entre clústeres pueda crear patrones que contengan `:` sin recibir una respuesta 500.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
elasticsearch
Área
api, backend, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.