Skip to content

[SIEM][Detection Engine] Adds privileges API endpoint - #52707

Merged
FrankHassanabad merged 6 commits into
elastic:masterfrom
FrankHassanabad:add-privileges
Dec 11, 2019
Merged

FrankHassanabad merged 6 commits into
elastic:masterfrom
FrankHassanabad:add-privileges

Conversation

@FrankHassanabad

@FrankHassanabad FrankHassanabad commented Dec 10, 2019 •

Copy link
Copy Markdown
Contributor

Summary

Adds a privileges API endpoint for the UI and people to query to check to see if their namespaced index is going to have the correct privileges or not.

Usage:

Testing:

Set up your user name and password to a test space for the CLI. Give whatever permissions
you want for restricted access to the test-space user, test-space role, and the test-space actual
space to ensure everything works out as expected.

export ELASTICSEARCH_USERNAME=test-space
export ELASTICSEARCH_PASSWORD=(passwword)
export SPACE_URL=/s/test-space

Then use it like so

API:

GET /api/detection_engine/privileges

CLI:

./get_privileges.sh

Return will be something like this:

{
  "username": "test-space",
  "has_all_requested": false,
  "cluster": {
    "monitor_ml": true,
    "manage_ccr": false,
    "manage_index_templates": true,
    "monitor_watcher": true,
    "monitor_transform": true,
    "read_ilm": true,
    "manage_api_key": false,
    "manage_security": false,
    "manage_own_api_key": false,
    "manage_saml": false,
    "all": false,
    "manage_ilm": true,
    "manage_ingest_pipelines": true,
    "read_ccr": false,
    "manage_rollup": true,
    "monitor": true,
    "manage_watcher": true,
    "manage": true,
    "manage_transform": true,
    "manage_token": false,
    "manage_ml": true,
    "manage_pipeline": true,
    "monitor_rollup": true,
    "transport_client": true,
    "create_snapshot": true
  },
  "index": {
    ".siem-signals-test-space": {
      "all": false,
      "manage_ilm": true,
      "read": false,
      "create_index": true,
      "read_cross_cluster": false,
      "index": false,
      "monitor": true,
      "delete": false,
      "manage": true,
      "delete_index": true,
      "create_doc": false,
      "view_index_metadata": true,
      "create": false,
      "manage_follow_index": true,
      "manage_leader_index": true,
      "write": false
    }
  },
  "application": {}
}

Example permissions that work for managing all signal indexes across all spaces so that the user in question can create it for each space:

Screen Shot 2019-12-10 at 4 48 19 PM

Example permissions that work for managing only a specific signal index:
Screen Shot 2019-12-10 at 3 49 24 PM

Example permissions that work for an end user using signals across all spaces:
Screen Shot 2019-12-10 at 3 49 41 PM

Example permissions that work for an end user using signals for a a specific index:
Screen Shot 2019-12-10 at 3 49 24 PM

Checklist

Use strikethroughs to remove checklist items you don't feel are applicable to this PR.

- [ ] This was checked for cross-browser compatibility, including a check against IE11

- [ ] Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n support

- [ ] Documentation was added for features that require explanation or tutorials

- [ ] This was checked for keyboard-only and screenreader accessibility

For maintainers

- [ ] This was checked for breaking API changes and was labeled appropriately

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@dhurley14 dhurley14 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The read_privelege code is super clean! Good catch with that missing await. Tested locally and looks and works great! LGTM

@elasticmachine

Copy link
Copy Markdown
Contributor

Pinging @elastic/siem (Team:SIEM)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants