Skip to content

Conversation

@Mikep86
Copy link
Contributor

@Mikep86 Mikep86 commented Nov 24, 2025

Updates the security framework to return a 404 when an invalid cluster alias is provided in a request. Previously, when security was enabled, a 403 was returned even when the user had (theoretical) access to the missing cluster.

@Mikep86 Mikep86 requested review from a team and slobodanadamovic November 24, 2025 21:45
@Mikep86 Mikep86 added >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC auto-backport Automatically create backport pull requests when merged branch:9.2 branch:9.1 branch:8.19 labels Nov 24, 2025
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

Copy link
Contributor

@slobodanadamovic slobodanadamovic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

As discussed internally, let's also adjust the now failing AuthorizationServiceTests.testUserWithNoRolesCannotPerformLocalSearch test.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Automatically create backport pull requests when merged >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team v8.19.9 v9.1.9 v9.2.3 v9.3.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants